Improper Privilege Management in Devolutions Server
CVE-2025-12485
Currently unrated
What is CVE-2025-12485?
The issue arises from inadequate privilege management during the handling of pre-MFA cookies in Devolutions Server versions 2025.3.5.0 and prior. This vulnerability allows low-privileged authenticated users to impersonate other accounts by reusing pre-MFA cookies. It's important to note that this vulnerability does not enable the bypassing of the multi-factor authentication (MFA) verification step of the targeted account, thereby maintaining a layer of security despite the impersonation risk.
Affected Version(s)
Server 0 <= 2025.3.5.0
