CVE-2025-55340
HIGH WAF: Low
CVSS 7.0
Published: 2025-10-14
CWE-287
Improper authentication in Windows Remote Desktop Protocol allows an authorized attacker to bypass a security feature locally.
WAF Coverage Analysis
Improper Authentication
Low WAF Coverage
OWASP: A07:2021 Identification and Authentication Failures
Affected Software
| Vendor | Product | Version |
|---|---|---|
| microsoft | windows_10_21h2 | up to 10.0.19044.6456 |
| microsoft | windows_10_22h2 | up to 10.0.19045.6456 |
| microsoft | windows_11_22h2 | up to 10.0.22621.6060 |
| microsoft | windows_11_23h2 | up to 10.0.22631.6060 |
| microsoft | windows_11_24h2 | up to 10.0.26100.6899 |
| microsoft | windows_11_25h2 | up to 10.0.26200.6899 |
| microsoft | windows_server_2022 | up to 10.0.20348.4294 |
| microsoft | windows_server_2022_23h2 | up to 10.0.25398.1913 |
| microsoft | windows_server_2025 | up to 10.0.26100.6899 |
References
- msrc.microsoft.com (Vendor Advisory)