Microsoft Windows Server 2025
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*
A vulnerability allowing an authorized attacker to bypass a security feature in Windows Remote Desktop Protocol (RDP) has been identified. This issue arises from improper authentication, enabling the bypass to occur locally. The vulnerability affects multiple Windows 10 and Windows 11 versions, as well as Windows Server 2022 and 2025.
Exploitation of this vulnerability could lead to unauthorized bypass of RDP authentication, allowing attackers to manipulate RDP sessions or associated security features.
Users can apply the security update KB5066791 for Windows 10, KB5066835 for Windows 11, and KB5066782 for Windows Server 2022. For Windows Server 2025, the same KB5066835 update is available. These security updates can be downloaded via the Microsoft Update Catalog.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.