CVE-2024-11672: Medium severity remote desktop manager vulnerability
Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an authenticated malicious user to bypass the "Add" permission via the import in vault feature.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11672?
CVE-2024-11672 is classified as a critical vulnerability due to its potential to allow unauthorized access to sensitive permissions.
How do I fix CVE-2024-11672?
To fix CVE-2024-11672, upgrade to Devolutions Remote Desktop Manager version 2024.2.22 or later.
Who is affected by CVE-2024-11672?
CVE-2024-11672 affects all users of Devolutions Remote Desktop Manager versions 2024.2.21 and earlier on Windows.
What type of vulnerability is CVE-2024-11672?
CVE-2024-11672 is an authorization vulnerability that allows an authenticated user to bypass permission controls.
What specific component is impacted by CVE-2024-11672?
CVE-2024-11672 impacts the add permission component within the import in vault feature of Devolutions Remote Desktop Manager.