CVE-2025-1635: Infoleak
Exposure of sensitive information in hub data source export feature in Devolutions Remote Desktop Manager 2024.3.29 and earlier on Windows allows a user exporting a hub data source to include his authenticated session in the export due to faulty business logic.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1635?
CVE-2025-1635 has been classified as a medium severity vulnerability due to its potential for exposing sensitive information.
How do I fix CVE-2025-1635?
To fix CVE-2025-1635, update Devolutions Remote Desktop Manager to version 2024.3.30 or later.
What is the impact of CVE-2025-1635 on users?
The impact of CVE-2025-1635 allows unauthorized users to export sensitive session information if exploited.
Can CVE-2025-1635 affect all users of Devolutions Remote Desktop Manager?
Yes, CVE-2025-1635 can affect all users of Devolutions Remote Desktop Manager versions up to 2024.3.29.
What are the recommended mitigation strategies for CVE-2025-1635?
The recommended mitigation strategy for CVE-2025-1635 is to promptly update the software to the latest version.