CVE-2025-2528: Devolutions Remote Desktop Manager
Low severity, CVSS 3.6. EPSS: 0.2% chance of exploitation in the next 30 days.
Improper authorization in application password policy in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a configuration different from the one mandated by the system administrators. This issue affects Remote Desktop Manager versions from 2025.1.24 through 2025.1.25, and all versions up to 2024.3.29.
Affected products
- Devolutions Remote Desktop Manager: before 2024.3.31.0 (fixed in 2024.3.31.0); from 2025.1.24.0, before 2025.1.26.0 (fixed in 2025.1.26.0)
Published 2025-03-26. Last modified 2026-06-17.