Cyber Security

Remote Desktop Manager Vulnerabilities Let Attackers Intercept Encrypted Communications

Devolutions have disclosed critical vulnerabilities in its Remote Desktop Manager (RDM) software, which could allow attackers to intercept and modify encrypted communications through man-in-the-middle (MITM) attacks. 

These flaws stem from improper certificate validation across all platforms and have been assigned high-severity CVE identifiers.

CVE-2025-1193 Improper Host Validation

CVE-2025-1193 has been assigned to this vulnerability, with a CVSS score of 8.5 (High). In RDM versions 2024.3.19 and earlier for Windows, the certificate validation logic failed to properly validate the host. 

The vulnerability in Windows arises from insufficient checks in the certificate validation logic within RDM’s host verification process.

Attackers can exploit this flaw by presenting a spoofed certificate for an unrelated host. This allows the interception of sensitive data during encrypted communication.

The attack vector is network-based, requiring no privileges or user interaction.

CVE-2024-11621 Missing Certificate Validation

This vulnerability is tracked as CVE-2024-11621, with a CVSS score of 8.6 (High). On macOS, Linux, Android, iOS, and PowerShell versions of RDM, certificate validation was entirely absent. 

This means any certificate presented during a connection would be accepted without user notification.

The complete absence of certificate validation creates a critical security gap where any malicious certificate is automatically trusted by the application. 

This enables attackers to use Man-in-the-Middle (MITM) attacks to intercept encrypted conversations.

Affected Products and Versions

PlatformAffected VersionsFixed Versions
Windows2024.3.19 and earlier2024.3.20 or higher
macOS2024.3.9.0 and earlier2024.3.10.3 or higher
Linux2024.3.2.5 and earlier2024.3.2.9 or higher
Android2024.3.3.7 and earlier2024.3.4.2 or higher
iOS2024.3.3.0 and earlier2024.3.4 or higher
PowerShell2024.3.6 and earlier2024.3.7 or higher

Devolutions recommend immediate upgrades to patched versions of RDM to mitigate these risks.

These vulnerabilities highlight the importance of robust certificate validation in securing encrypted communications against MITM attacks in remote desktop environments.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

16 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago