Debug Code in ExpressVPN Windows App Caused IP Leak via RDP Port

ExpressVPN has alerted users of a security issue in its Windows application that allowed certain Remote Desktop Protocol (RDP) traffic to bypass the VPN tunnel, potentially exposing users’ IP addresses. This vulnerability primarily affected TCP traffic routed over port 3389, the standard port for RDP connections, which are often used in enterprise environments rather than by typical consumers. The issue was discovered after a tip from a security researcher, prompting ExpressVPN’s engineers to re...

Save to Folder

Choose a folder to save this article: