CVE-2014-6318: Microsoft Windows 7
Medium severity, CVSS 4.3. EPSS: 11.4% chance of exploitation in the next 30 days.
The audit logon feature in Remote Desktop Protocol (RDP) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly log unauthorized login attempts supplying valid credentials, which makes it easier for remote attackers to bypass intended access restrictions via a series of attempts, aka "Remote Desktop Protocol (RDP) Failure to Audit Vulnerability."
Affected products
- Microsoft Windows 7: affected versions not specified
- Microsoft Windows 8: affected versions not specified
- Microsoft Windows 8.1: affected versions not specified
- Microsoft Windows Rt: affected versions not specified
- Microsoft Windows Rt 8.1: affected versions not specified
- Microsoft Windows Server 2008: affected versions not specified; version r2 only
- Microsoft Windows Server 2012: affected versions not specified; version r2 only
- Microsoft Windows Vista: affected versions not specified
Published 2014-11-11. Last modified 2026-06-17.