{"id":"CVE-2025-12485","title":"Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate another account by replaying the pre-MFA cookie.This does not bypass the target account MFA veri…","summary":"Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate another account by replaying the pre-MFA cookie.This does not bypass the target account MFA veri…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-269"],"vendor":"devolutions","product":"devolutions_server","affected":["devolutions_server < 2025.2.17.0","devolutions_server >= 2025.3.2.0, < 2025.3.6.0"],"patched":["devolutions_server 2025.3.6.0"],"published":"2025-11-06","updated":"2026-10-07","sourceUpdated":"2026-10-07T21:10:00.200","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-12485","references":[{"url":"https://devolutions.net/security/advisories/DEVO-2025-0016","label":"security@devolutions.net"}],"tags":["nvd"],"epss":0.00595,"epssPercentile":0.46769,"ingestedAt":"2026-10-07T21:54:14.964Z","slug":"CVE-2025-12485","body":"## Overview\n\nImproper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate another account by replaying the pre-MFA cookie.This does not bypass the target account MFA verification step.\n\n\n\n\n\nThis issue affects the following versions :\n\n  *  Devolutions Server 2025.3.2.0 through 2025.3.5.0\n  *  \n\nDevolutions Server 2025.2.15.0 and earlier\n\n## Affected\n\n- `devolutions_server < 2025.2.17.0`\n- `devolutions_server >= 2025.3.2.0, < 2025.3.6.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `devolutions_server 2025.3.6.0`","depth":"twilight","depthScore":49,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}