CVE-2024-12149: High severity remote desktop manager vulnerability
Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0 and earlier on Windows allows an authenticated user that request temporary permissions on an entry to obtain more privileges than requested.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12149?
CVE-2024-12149 is considered a high severity vulnerability due to incorrect permission assignment that allows users to gain more privileges than intended.
How do I fix CVE-2024-12149?
To fix CVE-2024-12149, users should update to Devolutions Remote Desktop Manager version 2024.3.19.1 or later, which addresses this permission issue.
Who is affected by CVE-2024-12149?
CVE-2024-12149 affects users of Devolutions Remote Desktop Manager versions up to and including 2024.3.19.0 on Windows.
What type of vulnerability is CVE-2024-12149?
CVE-2024-12149 is categorized as a permissions-related vulnerability, specifically involving temporary access requests.
Can an attacker exploit CVE-2024-12149 remotely?
Exploitation of CVE-2024-12149 requires authenticated access, making it unlikely to be exploited remotely by unauthenticated attackers.