← Back to CVE List

CVE-2025-2600

Published: 2025-03-26T18:15Z
Last Modified: 2025-04-01T15:16Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Improper authorization in the variable component in Devolutions Remote Desktop Manager on Windows allows an authenticated password to use the ELEVATED_PASSWORD variable even though not allowed by the "Allow password in variable policy". This issue affects Remote Desktop Manager versions from 2025.1.24 through 2025.1.25, and all versions up to 2024.3.29. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt