CVE-2024-11670: Medium severity remote desktop manager vulnerability
Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows a malicious authenticated user to bypass the "View Password" permission via specific actions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11670?
CVE-2024-11670 is classified as a high-severity vulnerability due to its potential for unauthorized access to sensitive information.
How do I fix CVE-2024-11670?
To mitigate CVE-2024-11670, upgrade Devolutions Remote Desktop Manager to version 2024.2.22 or later.
What types of systems are affected by CVE-2024-11670?
CVE-2024-11670 affects Devolutions Remote Desktop Manager versions 2024.2.21 and earlier running on Windows.
Who can exploit CVE-2024-11670?
A malicious authenticated user can exploit CVE-2024-11670 to bypass the "View Password" permission.
What is the nature of the vulnerability in CVE-2024-11670?
CVE-2024-11670 involves incorrect authorization in the permission validation component of the software.