CVE-2025-8312

7.1

Devolutions · Server

A deadlock in the Devolutions Server PAM automatic check-in feature allows passwords to remain valid past their intended check-out period.

Executive summary

A vulnerability in the Devolutions Server scheduling service allows passwords to persist beyond their authorized check-out window, posing a significant risk to privileged access security.

Vulnerability

This flaw involves a deadlock condition within the Privileged Access Management (PAM) automatic check-in mechanism, which prevents the system from properly revoking credentials after the allocated time. The vulnerability requires the attacker to have at least low-level (authenticated) access to interact with the system.

Business impact

The failure of the check-in service undermines the core integrity of the Privileged Access Management system, as credentials may remain active long after their intended expiration. With a CVSS score of 7.1, this high-severity issue could lead to unauthorized privilege escalation or extended access to sensitive resources, potentially facilitating lateral movement within the network.

Remediation

Immediate Action: Review the official Devolutions security advisory (DEVO-2025-0013) to identify and apply the necessary software updates or configuration patches as soon as they become available.

Proactive Monitoring: Monitor PAM scheduling logs for evidence of deadlocks or failures in the check-in process to identify accounts that may have retained access beyond their check-out period.

Compensating Controls: Manually audit and rotate credentials for accounts that have recently undergone check-out procedures until a permanent fix is applied to the scheduling service.

Exploitation status

Public Exploit Available: exploit_available (unknown)

Analyst recommendation

Given the potential for unauthorized access resulting from persistent credentials, organizations utilizing Devolutions Server should treat this as a high-priority maintenance item. Security teams must verify their current version and coordinate with their administrative teams to apply vendor-supplied patches immediately upon release to ensure the integrity of their privileged access lifecycle.

More Devolutions CVEs

Sources