ZeroHour

CVE-2024-11672

CVSS 3.1
4.3 medium
EPSS
<1%p44
Published
()
Modified
Description

Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an authenticated malicious user to bypass the "Add" permission via the import in vault feature.

Vendors
devolutions
Products
remote desktop manager
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.