CVE-2023-5766: Critical severity remote desktop manager vulnerability
Published Nov 1, 2023
·Updated
A remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to remotely execute code from another windows user session on the same host via a specially crafted TCP packet.
Affected Software
2 affected components
All of the following
Devolutions Remote Desktop Manager<=2023.2.33
Microsoft Windows
Event History
Nov 1, 2023
CVE Published
via MITRE·05:08 PM
Data Sourced
via MITRE·05:08 PM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2023-5766?
CVE-2023-5766 is a remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows.
2
How does CVE-2023-5766 work?
CVE-2023-5766 allows an attacker to remotely execute code from another Windows user session on the same host via a specially crafted TCP packet.
3
What software is affected by CVE-2023-5766?
Devolutions Remote Desktop Manager 2023.2.33 and earlier on Windows is affected by CVE-2023-5766.
4
What is the severity of CVE-2023-5766?
CVE-2023-5766 has a severity rating of 9.8 (critical).
5
How can I fix CVE-2023-5766?
To fix CVE-2023-5766, users should update to a version of Remote Desktop Manager that is later than 2023.2.33.