CVE-2024-11670: Devolutions Remote Desktop Manager

Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.

Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows a malicious authenticated user to bypass the "View Password" permission via specific actions.

Affected products

  • Devolutions Remote Desktop Manager: up to and including 2024.3.10.0

Published 2024-11-25. Last modified 2026-06-17.