CVE-2025-5334
📋 TL;DR
This vulnerability in Devolutions Remote Desktop Manager allows authenticated users to access private personal information when entries are unintentionally moved from user vaults to shared vaults during editing. It affects all major platform versions of Remote Desktop Manager 2025.1 and earlier.
💻 Affected Systems
- Devolutions Remote Desktop Manager
📦 What is this software?
⚠️ Risk & Real-World Impact
Worst Case
Sensitive credentials, personal data, and connection information are exposed to unauthorized authenticated users, potentially leading to lateral movement and data breaches.
Likely Case
Accidental exposure of user vault entries containing passwords, API keys, or connection details to other users with shared vault access.
If Mitigated
Limited exposure if strict access controls and vault segregation policies are already implemented.
🎯 Exploit Status
Exploitation requires authenticated access and specific editing actions that trigger the vault transfer bug.
🛠️ Fix & Mitigation
✅ Official Fix
Patch Version: Versions after those listed in affected systems (check vendor advisory for exact fixed versions)
Vendor Advisory: https://devolutions.net/security/advisories/DEVO-2025-0009
Restart Required: Yes
Instructions:
1. Update Remote Desktop Manager to the latest version. 2. Restart the application. 3. Verify no entries were unintentionally moved to shared vaults.
🔧 Temporary Workarounds
Disable entry editing in user vaults
allPrevent users from editing entries in their personal vaults to avoid triggering the bug
Audit shared vault permissions
allReview and restrict access to shared vaults to minimize exposure if entries are moved
🧯 If You Can't Patch
- Implement strict access controls and audit all shared vault entries regularly
- Educate users to avoid editing sensitive entries until patched and monitor for unusual access patterns
🔍 How to Verify
Check if Vulnerable:
Check your Remote Desktop Manager version against affected versions listed in the advisory
Check Version:
In RDM: Help → About (Windows/macOS) or Settings → About (mobile)
Verify Fix Applied:
Update to latest version and verify no entries appear unexpectedly in shared vaults
📡 Detection & Monitoring
Log Indicators:
- Unusual access patterns to shared vaults
- Multiple entry modifications in short timeframes
Network Indicators:
- Increased data transfers from RDM server if using centralized deployment
SIEM Query:
Search for RDM logs showing entry modifications followed by shared vault access events