An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to bypass permissions via batch custom PowerShell.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://devolutions.net | vendor advisory |
https://devolutions.net/security/advisories/DEVO-2021-0006 | vendor advisory |