Windows RDP Network Level Authentication Vulnerability
A new zero-day vulnerability in the Network Level Authentication (NLA) feature used by Microsoft's Remote Desktop Protocol (RDP) client has been discovered.
Summary
A new zero-day vulnerability in the Network Level Authentication (NLA) feature used by Microsoft's Remote Desktop Protocol (RDP) client has been discovered.
Affected platforms
The following platforms are known to be affected:
Threat details
A local, unauthenticated attacker could exploit this vulnerability to gain access to secure RDP sessions.
NLA is used to enhance the security of RDP sessions by requiring the user to authenticate prior to the session being created. In some versions of Windows, the handling of RDP sessions using NLA has changed. If a temporary RDP disconnect is triggered, the session will attempt an automatic reconnection. If successful, the session will be restored in an unlocked state, regardless of the state it was left before the disconnect. By introducing unexpected network activity, an attacker could trigger the vulnerability, at which point they would be able to access any affected session once they had reconnected.
This vulnerability also appears to bypass multi-factor authentication systems that integrate with the Windows login screen.
For further information:
Remediation steps
Last edited: 14 February 2020 2:46 pm