Microsoft RDP apparently allows you to log in with expired passwords – and apparently it has no plans to solve the problem


  • Security scientist Daniel Wade discovers worrying Microsoft RDP feature
  • This makes it possible to use old credentials when logging in
  • Microsoft has confirmed that it has no plans to change this

Security researcher Daniel Wade has discovered a protocol within Microsoft’s Remote Desktop Protocol (RDP), which allows users to log on to machines using recalled passwords.

Wade’s report warns “This is not just a mistake. It’s a breach of trust” that reminds Microsoft that people are changing their passwords that trust that this will “cut off unauthorized access”, making this feature completely modintuitive. Wade warned “millions of users – at home in small businesses or hybrid work – is unconsciously in danger.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top