Cyber Posture

CVE-2025-1193

High

Published: 10 February 2025

Published
10 February 2025
Modified
28 March 2025
KEV Added
Patch
CVSS Score 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
EPSS Score 0.0025 47.8th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Description

Improper host validation in the certificate validation component in Devolutions Remote Desktop Manager on 2024.3.19 and earlier on Windows allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack by presenting a certificate for a different host.

Security Summary

CVE-2025-1193, published on 2025-02-10, is an improper host validation vulnerability (CWE-295) in the certificate validation component of Devolutions Remote Desktop Manager versions 2024.3.19 and earlier on Windows. The flaw enables an attacker to conduct a man-in-the-middle (MITM) attack by presenting a certificate for a different host, allowing interception and modification of encrypted communications. It carries a CVSS v3.1 base score of 8.1 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N), indicating high severity due to its potential for significant confidentiality and integrity impacts.

A remote attacker requires no privileges and can exploit this over the network with low attack complexity, though user interaction is necessary. By positioning themselves between the client and the remote host—such as on a compromised network or via phishing—the attacker can present a fraudulent certificate, tricking the software into accepting it. Successful exploitation allows the attacker to intercept sensitive data in transit and modify communications, potentially leading to session hijacking, credential theft, or injection of malicious content.

Mitigation details are outlined in the vendor advisory DEVO-2025-0001, available at https://devolutions.net/security/advisories/DEVO-2025-0001/. Security practitioners should consult this reference for patching instructions and workarounds applicable to affected versions.

Details

CWE(s)
CWE-295

Affected Products

devolutions
remote desktop manager
≤ 2024.3.20.0 · ≤ 2024.3.20.0

References