CVE-2014-4861: Thycotic Secret Server

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

The Remote Desktop Launcher in Thycotic Secret Server before 8.6.000010 does not properly cleanup a temporary file that contains an encrypted password once a session has ended.

Affected products

  • Thycotic Secret Server: from 7.5.000000, up to and including 8.6.000009

Published 2018-03-09. Last modified 2026-06-17.