Improper Authorization in Devolutions Remote Desktop Manager on Windows
CVE-2025-2528
3.6LOW
What is CVE-2025-2528?
A vulnerability in Devolutions Remote Desktop Manager for Windows allows an authenticated user to bypass the intended application password policy, using a configuration that may not align with the settings enforced by system administrators. This could lead to unauthorized access, posing security risks to sensitive remote connections and data management.
Affected Version(s)
Remote Desktop Manager Windows 2025.1.24 <= 2025.1.25
Remote Desktop Manager Windows 0 <= 2024.3.29