CVE-2025-2562: Medium severity Devolutions Remote Desktop Manager vulnerability
Insufficient logging in the autotyping feature in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a stored password without generating a corresponding log event, via the use of the autotyping functionality.
This issue affects Remote Desktop Manager versions from 2025.1.24 through 2025.1.25, and all versions up to 2024.3.29.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2562?
CVE-2025-2562 has been classified as a medium-severity vulnerability due to insufficient logging in the autotyping feature.
How do I fix CVE-2025-2562?
To mitigate CVE-2025-2562, update Devolutions Remote Desktop Manager to versions later than 2025.1.25 or ensure proper logging practices.
Which versions of Devolutions Remote Desktop Manager are affected by CVE-2025-2562?
CVE-2025-2562 affects Remote Desktop Manager versions from 2025.1.24 up to and including 2024.3.29.
What is the impact of CVE-2025-2562 on users?
The impact of CVE-2025-2562 allows authenticated users to utilize stored passwords without generating log events, which can compromise security.
Is there a workaround for CVE-2025-2562 if I cannot update?
Currently, there are no specific workarounds documented for CVE-2025-2562, and it is recommended to apply the available updates.