Microsoft RDP apparently allows you to log in with expired passwords, and apparently has no plans to solve the problem


  • Security researcher Daniel Wade discovers the concern of the Microsoft RDP feature
  • This allows ancient credentials to be used at a log
  • Microsoft has confirmed that you have no plans to change this

Security researcher Daniel Wade has discovered a protocol within the Microsoft remote desktop protocol (RDP), which allows users to log in to machines using revoked passwords.

Wade’s report warns “This is not just a mistake. It is a breakdown of trust,” remembering Microsoft that people change their passwords trusting that this “will cut unauthorized access”, which makes this characteristic completely contradictory. Wade warned that “millions of users, at home, in small businesses or hybrid work configurations, are in knowledge without knowing it.

Leave a Comment

Your email address will not be published. Required fields are marked *