Skip to main content

Windows RDP Network Level Authentication Vulnerability

A new zero-day vulnerability in the Network Level Authentication (NLA) feature used by Microsoft's Remote Desktop Protocol (RDP) client has been discovered.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

A new zero-day vulnerability in the Network Level Authentication (NLA) feature used by Microsoft's Remote Desktop Protocol (RDP) client has been discovered.


Affected platforms

The following platforms are known to be affected:

Threat details

A local, unauthenticated attacker could exploit this vulnerability to gain access to secure RDP sessions.

NLA is used to enhance the security of RDP sessions by requiring the user to authenticate prior to the session being created. In some versions of Windows, the handling of RDP sessions using NLA has changed. If a temporary RDP disconnect is triggered, the session will attempt an automatic reconnection. If successful, the session will be restored in an unlocked state, regardless of the state it was left before the disconnect. By introducing unexpected network activity, an attacker could trigger the vulnerability, at which point they would be able to access any affected session once they had reconnected.

This vulnerability also appears to bypass multi-factor authentication systems that integrate with the Windows login screen.

For further information:


Remediation steps

Type Step

At the time of publication, Microsoft have not yet acknowledged the vulnerability. In the meantime, users and administrators are encouraged to apply the following workarounds where appropriate:

  • Limit access to the RDP client by locking the local system. Locking the remote system will not prevent remote access from a compromised system.
  • Disconnect RDP sessions instead of locking them. This will invalidate the current session and prevent automatic reconnection.

Last edited: 14 February 2020 2:46 pm