Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager allows an authenticated user to gain unauthorized access to private personal information. Under specific circumstances, entries may be unintentionally moved from user vaults to shared vaults when edited by their owners, making them accessible to other users. This issue affects the following versions : * Remote Desktop Manager Windows 2025.1.34.0 and earlier
History

Thu, 29 May 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 29 May 2025 15:00:00 +0000

Type Values Removed Values Added
Description Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager allows an authenticated user to gain unauthorized access to private personal information. Under specific circumstances, entries may be unintentionally moved from user vaults to shared vaults when edited by their owners, making them accessible to other users. This issue affects the following versions : * Remote Desktop Manager Windows 2025.1.34.0 and earlier
Weaknesses CWE-359
References

cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published: 2025-05-29T14:47:25.817Z

Updated: 2025-05-29T15:02:42.279Z

Reserved: 2025-05-29T14:04:27.697Z

Link: CVE-2025-5334

cve-icon Vulnrichment

Updated: 2025-05-29T15:02:29.720Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-29T15:15:34.650

Modified: 2025-05-30T16:31:03.107

Link: CVE-2025-5334

cve-icon Redhat

No data.