CVE-2025-1193: High severity remote desktop manager vulnerability
Improper host validation in the certificate validation component in Devolutions Remote Desktop Manager on 2024.3.19 and earlier on Windows allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack by presenting a certificate for a different host.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1193?
CVE-2025-1193 is considered critical due to its potential for man-in-the-middle attacks that could compromise encrypted communications.
How do I fix CVE-2025-1193?
To fix CVE-2025-1193, update Devolutions Remote Desktop Manager to version 2024.3.20 or later.
What systems are affected by CVE-2025-1193?
CVE-2025-1193 affects Devolutions Remote Desktop Manager versions up to 2024.3.19 on Windows.
What can an attacker do with CVE-2025-1193?
An attacker can intercept and modify encrypted communications by exploiting improper host validation due to CVE-2025-1193.
Is there a workaround for CVE-2025-1193?
The recommended solution for CVE-2025-1193 is to immediately update to the latest version, as there are no effective workarounds.