Executive brief
Devolutions Remote Desktop Manager, a platform used by IT teams to manage remote connections and credentials, is affected by a security flaw in its PowerShell VPN editor. An attacker with access to a shared workspace could trick the system into running a malicious script when another user attempts to launch a legitimate VPN connection. If successful, this allows the attacker to execute commands on the victim's computer with the victim's permissions, potentially leading to unauthorized data access or system compromise.
Technical details
A vulnerability classified as 'Use of Incorrectly-Resolved Name or Reference' (CWE-706) exists in the custom PowerShell VPN editor of Devolutions Remote Desktop Manager. The flaw stems from the application resolving VPN script links by display name rather than a unique identifier. An authenticated attacker with write access to a shared workspace can create a malicious script with a display name that collides with an existing, trusted VPN script link. When a victim attempts to execute the legitimate script, the application may resolve to and execute the attacker's script instead, leading to remote code execution in the victim's security context. The vulnerability is addressed in version 2026.2.12.0.
Affected products
- Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11
Timeline
- 2026-06-25: advisory: Initial publication by Devolutions
- 2026-06-26: disclosed: NVD publication date