CVE-2025-1193

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Feb 10, 2025
CWE ID 295

Summary

CVE-2025-1193 is a vulnerability affecting the certificate validation component in Devolutions Remote Desktop Manager versions 2024.3.19 and earlier on Windows. This issue results in improper host validation, enabling an attacker to execute man-in-the-middle attacks. By intercepting and modifying encrypted communications, the attacker can gain unauthorized access to sensitive data or impersonate a trusted host, potentially leading to significant security risks. Users are strongly advised to update their Remote Desktop Manager software to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Devolutions Remote Desktop Manager

Affected Vendors

  • Devolutions