Improper Privilege Management in Devolutions Server
CVE-2025-12485

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
6 November 2025

What is CVE-2025-12485?

The issue arises from inadequate privilege management during the handling of pre-MFA cookies in Devolutions Server versions 2025.3.5.0 and prior. This vulnerability allows low-privileged authenticated users to impersonate other accounts by reusing pre-MFA cookies. It's important to note that this vulnerability does not enable the bypassing of the multi-factor authentication (MFA) verification step of the targeted account, thereby maintaining a layer of security despite the impersonation risk.

Affected Version(s)

Server 2025.3.2.0 <= 2025.3.5.0

Server 0 <= 2025.2.15.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.