CVE-2024-7421
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2024-7421 is a newly disclosed vulnerability affecting Devolutions Remote Desktop Manager versions 2024.2.20.0 and older on Windows operating systems. This issue permits local attackers, who have access to system logs, to extract session credentials through passwords embedded in command-line arguments used to launch WinSCP sessions. This exposure poses a significant risk, as it enables unauthorized access to sensitive data and systems. Users are strongly advised to upgrade to the latest version of Devolutions Remote Desktop Manager to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Devolutions Remote Desktop Manager
Affected Vendors
- Devolutions