CVE-2025-1636: Infoleak
Exposure of sensitive information in My Personal Credentials password history component in Devolutions Remote Desktop Manager 2024.3.29 and earlier on Windows allows an authenticated user to inadvertently leak the My Personal Credentials in a shared vault via the clear history feature due to faulty business logic.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1636?
CVE-2025-1636 has a medium severity level due to the potential exposure of sensitive information.
How do I fix CVE-2025-1636?
To fix CVE-2025-1636, upgrade Devolutions Remote Desktop Manager to version 2024.3.30 or later.
What types of information are exposed by CVE-2025-1636?
CVE-2025-1636 can expose sensitive information from the My Personal Credentials password history.
Who is affected by CVE-2025-1636?
Any authenticated user of Devolutions Remote Desktop Manager version 2024.3.29 and earlier on Windows is affected by CVE-2025-1636.
Is there a workaround for CVE-2025-1636?
Currently, there is no official workaround for CVE-2025-1636 other than upgrading to the latest version.