CVE-2025-1193: Devolutions Remote Desktop Manager

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper host validation in the certificate validation component in Devolutions Remote Desktop Manager on 2024.3.19 and earlier on Windows allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack by presenting a certificate for a different host.

Affected products

  • Devolutions Remote Desktop Manager: before 2024.3.20.0 (fixed in 2024.3.20.0)

Published 2025-02-10. Last modified 2026-06-17.