CVE-2023-7047: Devolutions Remote Desktop Manager

Medium severity, CVSS 4.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Inadequate validation of permissions when employing remote tools and macros via the context menu within Devolutions Remote Desktop Manager versions 2023.3.31 and earlier permits a user to initiate a connection without proper execution rights via the remote tools feature. This affects only SQL data sources.

Affected products

  • Devolutions Remote Desktop Manager: up to and including 2023.3.31.0

Published 2023-12-21. Last modified 2026-06-17.