CVE-2025-8312
7.1Devolutions · Server
A deadlock in the Devolutions Server PAM automatic check-in feature allows passwords to remain valid past their intended check-out period.
Executive summary
A vulnerability in the Devolutions Server scheduling service allows passwords to persist beyond their authorized check-out window, posing a significant risk to privileged access security.
Vulnerability
This flaw involves a deadlock condition within the Privileged Access Management (PAM) automatic check-in mechanism, which prevents the system from properly revoking credentials after the allocated time. The vulnerability requires the attacker to have at least low-level (authenticated) access to interact with the system.
Business impact
The failure of the check-in service undermines the core integrity of the Privileged Access Management system, as credentials may remain active long after their intended expiration. With a CVSS score of 7.1, this high-severity issue could lead to unauthorized privilege escalation or extended access to sensitive resources, potentially facilitating lateral movement within the network.
Remediation
Immediate Action: Review the official Devolutions security advisory (DEVO-2025-0013) to identify and apply the necessary software updates or configuration patches as soon as they become available.
Proactive Monitoring: Monitor PAM scheduling logs for evidence of deadlocks or failures in the check-in process to identify accounts that may have retained access beyond their check-out period.
Compensating Controls: Manually audit and rotate credentials for accounts that have recently undergone check-out procedures until a permanent fix is applied to the scheduling service.
Exploitation status
Public Exploit Available: exploit_available (unknown)
Analyst recommendation
Given the potential for unauthorized access resulting from persistent credentials, organizations utilizing Devolutions Server should treat this as a high-priority maintenance item. Security teams must verify their current version and coordinate with their administrative teams to apply vendor-supplied patches immediately upon release to ensure the integrity of their privileged access lifecycle.