CVE-2024-11672 Information
Nov 26, 2024
cve
Description
Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an authenticated malicious user to bypass the \Add\ permission via the import in vault feature.
Reference
https://devolutions.net/security/advisories/DEVO-2024-0016
Share on: