Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0 and earlier on Windows allows an authenticated user that request temporary permissions on an entry to obtain more privileges than requested.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-50628 | Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0 and earlier on Windows allows an authenticated user that request temporary permissions on an entry to obtain more privileges than requested. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2024-0017 |
|
History
Fri, 28 Mar 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:free:windows:*:* cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:team:windows:*:* |
Thu, 05 Dec 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Devolutions
Devolutions remote Desktop Manager |
|
| CPEs | cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Devolutions
Devolutions remote Desktop Manager |
|
| Metrics |
cvssV3_1
|
Wed, 04 Dec 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0 and earlier on Windows allows an authenticated user that request temporary permissions on an entry to obtain more privileges than requested. | |
| Weaknesses | CWE-732 | |
| References |
|
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published:
Updated: 2024-12-05T18:46:29.926Z
Reserved: 2024-12-04T13:27:48.580Z
Link: CVE-2024-12149
Updated: 2024-12-05T18:46:22.340Z
Status : Analyzed
Published: 2024-12-04T18:15:12.350
Modified: 2025-03-28T16:21:47.753
Link: CVE-2024-12149
No data.
OpenCVE Enrichment
No data.
EUVD