CVE-2024-3545: Medium severity remote desktop manager vulnerability
Improper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earlier on windows and Devolutions Server 2024.1.8 and earlier allows an attacker to access sensitive informations contained in the offline cache file by gaining access to a computer where the software is installed even though the offline mode is disabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3545?
CVE-2024-3545 is considered a critical vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2024-3545?
To fix CVE-2024-3545, upgrade Devolutions Remote Desktop Manager to version 2024.1.21 or later and Devolutions Server to version 2024.1.9 or later.
What types of systems are vulnerable to CVE-2024-3545?
CVE-2024-3545 affects Devolutions Remote Desktop Manager versions 2024.1.20 and earlier, as well as Devolutions Server versions 2024.1.8 and earlier on Windows.
What information can be accessed due to CVE-2024-3545?
CVE-2024-3545 allows attackers with physical access to exploit improper permission handling and access sensitive information in the vault offline cache file.
Is CVE-2024-3545 being actively exploited?
As of the latest updates, there are indications that CVE-2024-3545 is being targeted by attackers, emphasizing the importance of applying the necessary patches.