CVE-2023-5766: Devolutions Remote Desktop Manager

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

A remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to remotely execute code from another windows user session on the same host via a specially crafted TCP packet.

Affected products

  • Devolutions Remote Desktop Manager: up to and including 2023.2.33

Published 2023-11-01. Last modified 2026-06-17.