PT-2025-23168 · Devolutions · Devolutions Remote Desktop Manager

Published

2025-05-29

·

Updated

2025-07-02

·

CVE-2025-5334

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Devolutions Remote Desktop Manager versions 2025.1.34.0 and earlier
Description The issue allows an authenticated user to gain unauthorized access to private personal information in the user vaults component. Under specific circumstances, entries may be unintentionally moved from user vaults to shared vaults when edited by their owners, making them accessible to other users.
Recommendations For Devolutions Remote Desktop Manager versions 2025.1.34.0 and earlier, update to a version that contains a fix for this issue to prevent unauthorized access to private personal information. As a temporary workaround, consider restricting access to the user vaults component to minimize the risk of exploitation. Avoid editing entries in user vaults until the issue is resolved to prevent unintentional movement of entries to shared vaults.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-5334

Affected Products

Devolutions Remote Desktop Manager