CVE-2025-12485: High severity Devolutions Server vulnerability
Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate another account by replaying the pre-MFA cookie.This does not bypass the target account MFA verification step.
This issue affects the following versions :
Devolutions Server 2025.3.2.0 through 2025.3.5.0
Devolutions Server 2025.2.15.0 and earlier
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12485?
CVE-2025-12485 is rated as a high-severity vulnerability due to its potential for account impersonation.
How do I fix CVE-2025-12485?
To remediate CVE-2025-12485, upgrade Devolutions Server to version 2025.3.5.1 or later, which addresses the privilege management issue.
What are the potential impacts of CVE-2025-12485?
CVE-2025-12485 could allow a low-privileged user to access another user's account by replaying the pre-MFA cookie, compromising account integrity.
Which versions of Devolutions Server are affected by CVE-2025-12485?
CVE-2025-12485 affects Devolutions Server versions up to and including 2025.3.5.0.
Does CVE-2025-12485 bypass MFA validation?
No, while CVE-2025-12485 allows impersonation, it does not bypass the target account's MFA verification steps.