Devolutions Server
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*
- <= 2025.1.7.0
A privilege escalation vulnerability has been identified in Devolutions Server versions through 2025.1.7.0. The issue arises from improper access control in user group management, allowing non-administrative users with 'User Management' and 'User Group Management' permissions to add users to groups with administrative privileges.
Exploitation of this vulnerability allows for unauthorized privilege escalation, enabling users to gain administrative rights they should not have.
Users are advised to upgrade to Devolutions Server version 2025.1.9.0 or higher.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.