Improper access control in user group management in Devolutions Server 2025.1.7.0 and earlier allows a non-administrative user with both "User Management" and "User Group Management" permissions to perform privilege escalation by adding users to groups with administrative privileges.
CVE ID: CVE-2025-4433
Vendor: Devolutions
Product: Server
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 9.05% (scored less or equal to compared to others)
EPSS Date: 2025-06-08 (when was this score calculated)