CVE-2026-40372
CVSS 9.1 CRITICAL: improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate… EPSS 11% (95th percentile). Microsoft patch: 5091596.
Patch available KB5091596 Download →
Vulnerabilities · 144 days ago
The new Remote Desktop warning is meant to stop users from blindly opening .rdp files. A display bug can hide or distort that prompt on some systems, which leaves the anti-phishing control in place only on paper.
Microsoft says the April 14 Windows update adds the warning for Remote Desktop files on Windows 11 and other supported Windows versions, tied to CVE-2026-40372. The Known Issues entry says the message may not render correctly when monitors use different scaling settings, such as 100 percent and 125 percent.
That turns a security change into a usability trap. Users who cannot read or use the prompt can still be pushed into accepting connection settings they were supposed to review, so the protection loses much of its value until Microsoft fixes the rendering bug.
CVSS 9.1 CRITICAL: improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate… EPSS 11% (95th percentile). Microsoft patch: 5091596.
Patch available KB5091596 Download →
1 source covering this story
Remote Desktop security beefed up with hard-to-read messages
: Ailing scaling blamed by Windows-maker for unreadable missives
Part of the PlainSec briefing for 2026-04-25