Microsoft RDP apparently lets you log in with expired passwords – and it apparently doesn’t have plans to fix the issue

zeeforce
3 Min Read




  • Security researcher Daniel Wade discovers worrying Microsoft RDP feature
  • This allows old credentials to be used when logging in
  • Microsoft has confirmed it has no plans to change this

Security researcher Daniel Wade has discovered a protocol within Microsoft’s Remote Desktop Protocol (RDP), which allows users to log into machines using revoked passwords.

Wade’s report warns “this isn’t just a bug. It’s a trust breakdown,” reminding Microsoft that people change their passwords trusting that this will “cut off unauthorized access”, making this feature entirely counter-intuitive. Wade cautioned “millions of users—at home, in small businesses, or hybrid work setups—are unknowingly at risk.



Source link

Share This Article
Leave a comment
Optimized by Optimole
Verified by MonsterInsights