← Back

CVE-2024-12149

nvd nist
Published: Dec 4, 2024Modified: Jun 17, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.8 / Impact: 5.2
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0 and earlier on Windows allows an authenticated user that request temporary permissions on an entry to obtain more privileges than requested.

Affected (2)

1 product
Remote Desktop Manager
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Devolutions
Before 2024.3.20.0
Before 2024.3.20.0

References (1)

Source: security@devolutions.net
Vendor Advisory

Timeline

No history available yet.