Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-12149


Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0 and earlier on Windows allows an authenticated user that request temporary permissions on an entry to obtain more privileges than requested.


Published

2024-12-04T18:15:12.350

Last Modified

2025-03-28T16:21:47.753

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-732
  • Type: Primary
    CWE-732

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application devolutions remote_desktop_manager < 2024.3.20.0 Yes
Application devolutions remote_desktop_manager < 2024.3.20.0 Yes

References