CVE-2022-3641: High severity remote desktop manager vulnerability
Published Dec 7, 2022
·Updated
Elevation of privilege in the Azure SQL Data Source in Devolutions Remote Desktop Manager 2022.3.13 to 2022.3.24 allows an authenticated user to spoof a privileged account.
Affected Software
1 affected component
Devolutions Remote Desktop Manager>=2022.3.13<2022.3.26
Event History
Dec 7, 2022
CVE Published
via MITRE·02:35 PM
Data Sourced
via MITRE·02:35 PM
Description
Dec 12, 2022
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this elevation of privilege vulnerability?
The vulnerability ID for this elevation of privilege vulnerability is CVE-2022-3641.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Elevation of privilege in the Azure SQL Data Source in Devolutions Remote Desktop Manager 2022.3.13'.
3
What is the severity of CVE-2022-3641?
The severity of CVE-2022-3641 is high with a CVSS score of 8.8.
4
Which software versions are affected by CVE-2022-3641?
Versions 2022.3.13 to 2022.3.24 of Devolutions Remote Desktop Manager are affected by CVE-2022-3641.
5
How can an authenticated user exploit CVE-2022-3641?
An authenticated user can exploit CVE-2022-3641 to spoof a privileged account.
6
Where can I find more information about CVE-2022-3641?
More information about CVE-2022-3641 can be found at https://devolutions.net/security/advisories/DEVO-2022-0010.