CVE-2025-12485
8.8Devolutions · Devolutions Server
A privilege management flaw in Devolutions Server allows authenticated users to impersonate other accounts by replaying pre-MFA cookies, though it does not bypass the target account MFA requirement.
Executive summary
A high-severity privilege management vulnerability in Devolutions Server allows authenticated attackers to perform account impersonation, presenting a significant risk to organizational access control.
Vulnerability
The software exhibits improper privilege management regarding pre-MFA cookie handling. An authenticated low-privileged user can replay a pre-MFA cookie to impersonate another user session, though the vulnerability does not bypass the target account's multi-factor authentication check.
Business impact
The ability for a low-privileged user to impersonate other accounts poses a severe risk to internal data confidentiality and system integrity. Given the CVSS score of 8.8, this vulnerability could facilitate unauthorized lateral movement or the escalation of privileges within the Devolutions environment. Such unauthorized access can lead to significant data exfiltration or the compromise of sensitive administrative configurations.
Remediation
Immediate Action: Review the official Devolutions security advisory (DEVO-2025-0016) and apply the necessary security updates as soon as they are made available by the vendor.
Proactive Monitoring: Security teams should audit system access logs for anomalous session activity or repeated attempts to initiate authentication sequences from single user accounts.
Compensating Controls: Ensure that multi-factor authentication is enforced globally across all user accounts to limit the utility of replayed cookies, and monitor for unusual traffic patterns originating from internal user segments.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability represents a significant risk to the security posture of the Devolutions Server platform. Administrators should prioritize the identification of affected instances within their infrastructure and prepare to deploy patches immediately upon their release. Maintaining strict adherence to MFA policies remains the most effective defense against the impact of this session-based exploitation vector.