Devolutions Server Privileged Access Management JIT Elevation Vulnerability

Vulnerability

A vulnerability exists in the Just-In-Time (JIT) elevation feature of Privileged Access Management (PAM) within Devolutions Server versions through 2025.1.5.0. The issue arises from an incorrect privilege assignment that allows a PAM user to elevate a previously configured user account. This flaw occurs because the system fails to update the internal account's Security Identifier (SID) when the username is changed, enabling unauthorized privilege escalation.

Impact

Exploitation of this vulnerability could lead to unauthorized elevation of privileges for PAM users, allowing them to gain elevated rights on accounts that were improperly managed due to the SID update failure.

Remediation

Users are advised to upgrade to Devolutions Server version 2025.1.6.0 or higher.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
5.0
exploitability
4.8
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.