Microsoft RDP apparently allows you to connect with expired passwords – and it apparently does not intend to solve the problem


  • Security researcher Daniel Wade discovers a disturbing Microsoft RDP functionality
  • This allows you to use old identification information when connection
  • Microsoft confirmed that he did not intend to change this

Security researcher Daniel Wade discovered a protocol in the remote office protocol of Microsoft (RDP), which allows users to connect to machines using passwords revoked.

Wade’s report warns “it’s not just a bug. It is a breakdown of confidence “, reminding Microsoft that people change their passwords by trusting that this will cut unauthorized access”, which makes this functionality fully counter-intuitive. Wade warned that “millions of users – at home, in small businesses or hybrid work configurations – are at risk without knowing it.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top