Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager
allows an authenticated user to gain unauthorized access to private personal information.
Under specific circumstances, entries may be unintentionally moved from user vaults to shared vaults when edited by their owners, making them accessible to other users.
This issue affects the following versions :
* Remote Desktop Manager Windows 2025.1.34.0 and earlier
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://devolutions.net/security/advisories/DEVO-2025-0009 |
![]() ![]() |
History
Thu, 29 May 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-200 | |
Metrics |
cvssV3_1
|
Thu, 29 May 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager allows an authenticated user to gain unauthorized access to private personal information. Under specific circumstances, entries may be unintentionally moved from user vaults to shared vaults when edited by their owners, making them accessible to other users. This issue affects the following versions : * Remote Desktop Manager Windows 2025.1.34.0 and earlier | |
Weaknesses | CWE-359 | |
References |
|

Status: PUBLISHED
Assigner: DEVOLUTIONS
Published: 2025-05-29T14:47:25.817Z
Updated: 2025-05-29T15:02:42.279Z
Reserved: 2025-05-29T14:04:27.697Z
Link: CVE-2025-5334

Updated: 2025-05-29T15:02:29.720Z

Status : Awaiting Analysis
Published: 2025-05-29T15:15:34.650
Modified: 2025-05-30T16:31:03.107
Link: CVE-2025-5334

No data.