Horizon Alert
Summary of the vulnerability and why it matters
This vulnerability in Devolutions Server allows authenticated users to potentially approve access requests for others, leading to unauthorized access to sensitive information. The primary concern is confirming if your organization uses the affected product and is potentially exposed.
- Unauthorized users can gain access.
- Protects sensitive vault and entry data.
- Confirm relevance and exposure immediately.
Attack Path
How an attacker could exploit the issue
An attacker with basic authenticated access could potentially exploit this vulnerability by crafting specific API requests. The attacker would start by logging into Devolutions Server with a basic user account. They would then use this access to manipulate the temporary access workflow, allowing them to approve their own or others' temporary access requests. This could grant them unauthorized access to sensitive vaults and entries.
- Requires basic authenticated access.
- Triggers via crafted API requests.
- Leads to unauthorized vault access.
Live Threat
Current exploitation, exposure, and threat context
An authenticated basic user could exploit an improper authorization flaw in Devolutions Server's temporary access workflow to self-approve or approve access requests from other users. This could lead to unauthorized access to sensitive vaults and entries when crafted API requests are used.
- Access to vaults and entries.
- Crafted API requests can bypass controls.
- Unauthorized access to sensitive data.
Operational Fix
Recommended remediation, mitigation, and detection steps
Application owners responsible for Devolutions Server deployments are likely the first point of contact for addressing this vulnerability. The immediate priority should be identifying all instances of the affected software, assessing their business criticality and external reachability, and confirming the accountable owner for each. Once identified, a remediation plan can be developed based on the assessed risk.
- Confirm Devolutions Server instance ownership.
- Verify external exposure and asset criticality.
- Plan remediation or implement compensating controls.