CVE-2024-12149

HIGH

Devolutions Remote Desktop Manager < 2024.3.20.0 - Authenticated Privilege Escalation via Temporary Access Requests

Title source: llm
STIX 2.1

Description

Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0 and earlier on Windows allows an authenticated user that request temporary permissions on an entry to obtain more privileges than requested.

References (1)

Core 1

Scores

CVSS v3 8.1
EPSS 0.0058
EPSS Percentile 43.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-732
Status published
Products (1)
devolutions/remote_desktop_manager < 2024.3.20.0 (2 CPE variants)
Published Dec 04, 2024
Tracked Since Feb 18, 2026