CVE-2025-5334 – Devolutions Remote Desktop Manager Private Data Exposure and Unauthorized Access

The following table lists the changes that have been made to the
CVE-2025-5334 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    May. 29, 2025

    Action Type Old Value New Value
    Added Description Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager
    allows an authenticated user to gain unauthorized access to private personal information.

    Under specific circumstances, entries may be unintentionally moved from user vaults to shared vaults when edited by their owners, making them accessible to other users.

    This issue affects the following versions :

    * Remote Desktop Manager Windows 2025.1.34.0 and earlier

    Added CWE CWE-359
    Added Reference https://devolutions.net/security/advisories/DEVO-2025-0009
  • CVE Modified
    by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    May. 29, 2025

    Action Type Old Value New Value
    Added CVSS V3.1 AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
    Added CWE CWE-200
Share the Post:

Related Posts