CVE-2025-1635

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Mar 13, 2025
Updated: Mar 28, 2025
CWE ID 200

Summary

CVE-2025-1635 is a vulnerability affecting Devolutions Remote Desktop Manager 2024.3.29 and earlier versions on Windows. This issue exposes sensitive information, as a user exporting a hub data source can inadvertently include their authenticated session in the export due to flawed business logic. This could potentially lead to unauthorized access to secure data for attackers who obtain the exported file. Organizations using these versions of Devolutions RDM are urged to update to a patched version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Devolutions Remote Desktop Manager

Affected Vendors

  • Devolutions