CVE-2025-4433: High severity devolutions server vulnerability
Improper access control in user group management in Devolutions Server 2025.1.7.0 and earlier allows a non-administrative user with both "User Management" and "User Group Management" permissions to perform privilege escalation by adding users to groups with administrative privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4433?
CVE-2025-4433 is rated as a high-severity vulnerability due to its ability to allow privilege escalation.
How do I fix CVE-2025-4433?
To fix CVE-2025-4433, upgrade Devolutions Server to version 2025.1.8.0 or later to mitigate the improper access control issue.
Who is affected by CVE-2025-4433?
CVE-2025-4433 affects users of Devolutions Server version 2025.1.7.0 and earlier who have user management permissions.
What type of vulnerability is CVE-2025-4433?
CVE-2025-4433 is an improper access control vulnerability that allows non-administrative users to escalate privileges.
Can a non-administrative user exploit CVE-2025-4433?
Yes, a non-administrative user with specific permissions can exploit CVE-2025-4433 to gain administrative privileges.