CVE-2025-50171

9.1

Microsoft · Windows Remote Desktop Server

A missing authorization vulnerability in the Windows Remote Desktop Server allows unauthenticated attackers to perform network-based spoofing.

Executive summary

A critical authorization flaw in Microsoft Windows Remote Desktop Server exposes systems to spoofing attacks by unauthenticated network actors.

Vulnerability

This vulnerability is a missing authorization flaw (CWE-862) located within the Remote Desktop Server component. It allows an unauthenticated attacker to initiate spoofing actions over the network without requiring any prior user interaction or valid credentials.

Business impact

The ability for an unauthenticated attacker to spoof network traffic poses a severe threat to internal network integrity and session security. Given the high CVSS score of 9.1, this flaw could be leveraged to facilitate man-in-the-middle attacks, impersonate trusted services, or bypass authentication controls, leading to unauthorized access and potential data exfiltration.

Remediation

Immediate Action: Apply the relevant security updates provided by Microsoft in the August 2025 security release to the affected Windows builds immediately.

Proactive Monitoring: Monitor network traffic for unusual Remote Desktop Protocol (RDP) activity, specifically looking for unexpected connection attempts or authentication patterns that deviate from established baselines.

Compensating Controls: Restrict access to Remote Desktop services via network firewalls to trusted IP addresses only, and implement VPN requirements to minimize exposure to untrusted network segments.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the critical severity of this vulnerability and the potential for unauthenticated network-based exploitation, organizations must prioritize the deployment of the provided security patches across all affected Windows endpoints. Failure to remediate this flaw leaves infrastructure susceptible to spoofing and unauthorized network manipulation, necessitating an urgent patching cycle.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section
  3. Published in the daily brief critical section
  4. Analyst report written
  5. Fix documented version 10.0.19044.6216 per CVE record

Sources