CVE-2024-7421: Medium severity remote desktop manager vulnerability
An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials via passwords included in command-line arguments when launching WinSCP sessions
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7421?
CVE-2024-7421 is rated as a medium severity vulnerability due to potential information exposure.
How do I fix CVE-2024-7421?
To mitigate CVE-2024-7421, update Devolutions Remote Desktop Manager to version 2024.3.10 or later, which addresses this vulnerability.
What type of information is exposed in CVE-2024-7421?
CVE-2024-7421 exposes session credentials found in command-line arguments used when launching WinSCP sessions.
Who is affected by CVE-2024-7421?
Users of Devolutions Remote Desktop Manager version 2024.2.20.0 and earlier on Windows are affected by CVE-2024-7421.
Can local attackers exploit CVE-2024-7421?
Yes, local attackers with access to system logs can exploit CVE-2024-7421 to obtain sensitive information.