CVE-2025-2528

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 26, 2025
Updated: Mar 27, 2025
CWE ID 150
CWE ID 157

Summary

CVE-2025-2528 is a vulnerability affecting the application password policy in Devolutions Remote Desktop Manager on Windows. An authenticated user can bypass system administrators' mandated password policies, using a configuration of their choice instead. This issue poses a security risk, as it allows unauthorized access or weaker passwords. It affects Remote Desktop Manager versions from 2025.1.24 to 2025.1.25 and all versions up to 2024.3.29. Users are advised to update to a patched version as soon as possible to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share