CVE-2025-12485 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate another account by…
High CVSS: 8.8

CVE-2025-12485

Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate another account by replaying the pre-MFA cookie.This does not bypass the target account MFA verification step.





This issue affects the following versions :

* Devolutions Server 2025.3.2.0 through 2025.3.5.0
*

Devolutions Server 2025.2.15.0 and earlier
Vendor
Devolutions
Product
Devolutions Server
CWE
CWE-269
Yayın Tarihi
2025-11-06 17:15:42
Güncelleme
2025-11-10 16:31:06
Source Identifier
security@devolutions.net
KEV Date Added
-

Kategoriler

Referanslar