Improper Privilege Management in Devolutions Server
CVE-2025-12485

Currently unrated

Key Information:

Status
Vendor
CVE Published:
6 November 2025

What is CVE-2025-12485?

The issue arises from inadequate privilege management during the handling of pre-MFA cookies in Devolutions Server versions 2025.3.5.0 and prior. This vulnerability allows low-privileged authenticated users to impersonate other accounts by reusing pre-MFA cookies. It's important to note that this vulnerability does not enable the bypassing of the multi-factor authentication (MFA) verification step of the targeted account, thereby maintaining a layer of security despite the impersonation risk.

Affected Version(s)

Server 0 <= 2025.3.5.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-12485 : Improper Privilege Management in Devolutions Server