CVE-2024-11671: Medium severity remote desktop manager vulnerability
Published Nov 25, 2024
·Updated
Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an authenticated user to bypass the MFA validation via data source switching.
Affected Software
3 affected components
Devolutions Remote Desktop Manager<=2024.3.17
Devolutions Remote Desktop Manager Windows<2024.3.18.0
Devolutions Remote Desktop Manager Windows<2024.3.18.0
Event History
Nov 25, 2024
CVE Published
via MITRE·02:46 PM
Data Sourced
via MITRE·02:46 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-11671?
CVE-2024-11671 has a medium severity level due to improper authentication vulnerabilities.
2
How do I fix CVE-2024-11671?
To remediate CVE-2024-11671, upgrade Devolutions Remote Desktop Manager to version 2024.3.18 or later.
3
What does CVE-2024-11671 affect?
CVE-2024-11671 affects Devolutions Remote Desktop Manager versions up to and including 2024.3.17.
4
Can CVE-2024-11671 be exploited remotely?
CVE-2024-11671 cannot be exploited remotely as it requires authentication and involves data source switching.
5
What impact does CVE-2024-11671 have on user accounts?
CVE-2024-11671 allows an authenticated user to bypass multi-factor authentication, posing a risk to account security.