Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-4417: Devolutions

Improper access controls in the entry duplication component in Devolutions Remote Desktop Manager 2023.2.19 and earlier versions on Windows allows an authenticated user, under specific circumstances, to inadvertently share their personal vault entry with shared vaults via an incorrect vault in the duplication write process.

CVE
#vulnerability#mac#windows#auth

DEVO-2023-0015****Summary

Remote Desktop Manager Windows is affected by multiple security vulnerabilities.

Affected Products

Remote Desktop Manager Windows

Change Log

Initial Publication - 2023-08-21

Severity

Medium

Product

Remote Desktop Manager Windows

Fix Version

2023.2.22

Unauthorized Connection Exploit via Remote Tools in Remote Desktop Manager****Description

Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 and earlier permits a user to initiate a connection without proper execution rights via the remote tools feature.

Remediation and Workarounds

Upgrade to Remote Desktop Manager Windows 2023.2.22 and higher.

Severity

Medium - 3.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected Products

Remote Desktop Manager Windows 2023.2.19 and earlier.

CVE(s)

CVE-2023-4373

Incorrect vault used for the duplicate entry feature.****Description

Improper access controls in the entry duplication component in Devolutions Remote Desktop Manager 2023.2.19 and earlier versions on Windows allows an authenticated user, under specific circumstances, to inadvertently share their personal vault entry with shared vaults via an incorrect vault in the duplication write process.

Remediation and Workarounds

Upgrade to Remote Desktop Manager Windows 2023.2.22 and higher.

Severity

Medium - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N 5.7

Affected Products

Remote Desktop Manager Windows 2023.2.19 and earlier.

CVE(s)

CVE-2023-4417

Related news

CVE-2023-4373: Devolutions

Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 and earlier permits a user to initiate a connection without proper execution rights via the remote tools feature.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907