Tech

Microsoft RDP apparently lets you log in with expired passwords – and it apparently doesn’t have plans to fix the issue

Share
Share


  • Security researcher Daniel Wade discovers worrying Microsoft RDP feature
  • This allows old credentials to be used when logging in
  • Microsoft has confirmed it has no plans to change this

Security researcher Daniel Wade has discovered a protocol within Microsoft’s Remote Desktop Protocol (RDP), which allows users to log into machines using revoked passwords.

Wade’s report warns “this isn’t just a bug. It’s a trust breakdown,” reminding Microsoft that people change their passwords trusting that this will “cut off unauthorized access”, making this feature entirely counter-intuitive. Wade cautioned “millions of users—at home, in small businesses, or hybrid work setups—are unknowingly at risk.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Microsoft is making all new accounts passwordless by default
Tech

Microsoft is making all new accounts passwordless by default

New Microsoft accounts will use passkeys by default, company reveals Existing users...