Improper access controls in the entry duplication component in Devolutions Remote Desktop Manager 2023.2.19 and earlier versions on Windows allows an authenticated user, under specific circumstances, to inadvertently share their personal vault entry with shared vaults via an incorrect vault in the duplication write process.
References
Link | Resource |
---|---|
https://devolutions.net/security/advisories/DEVO-2023-0015 | Vendor Advisory |
https://devolutions.net/security/advisories/DEVO-2023-0015 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 08:35
Type | Values Removed | Values Added |
---|---|---|
References | () https://devolutions.net/security/advisories/DEVO-2023-0015 - Vendor Advisory |
25 Aug 2023, 17:55
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-Other | |
CPE | cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
First Time |
Devolutions remote Desktop Manager
Devolutions Microsoft windows Microsoft |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
References | (MISC) https://devolutions.net/security/advisories/DEVO-2023-0015 - Vendor Advisory |
22 Aug 2023, 19:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-21 19:15
Updated : 2024-11-21 08:35
NVD link : CVE-2023-4417
Mitre link : CVE-2023-4417
CVE.ORG link : CVE-2023-4417
JSON object : View
Products Affected
microsoft
- windows
devolutions
- remote_desktop_manager
CWE