ExpressVPN has released a caller spot for its Windows app to adjacent a vulnerability that tin time off distant desktop postulation unprotected. If you usage ExpressVPN connected Windows, download type 12.101.0.45 arsenic soon arsenic possible, particularly if you usage Remote Desktop Protocol (RDP) aliases immoderate different postulation done TCP larboard 3389.
ExpressVPN announced some nan vulnerability and nan hole successful a blog post earlier this week. According to that post, an independent interrogator going by Adam-X sent successful a extremity connected April 25 to declare a reward from ExpressVPN's bug bounty program. Adam-X noticed that immoderate soul debug codification which near postulation connected TCP larboard 3389 unprotected had mistakenly shipped to customers. ExpressVPN released nan spot astir 5 days later successful type 12.101.0.45 for Windows.
As ExpressVPN points retired successful its announcement of nan patch, it's improbable that nan vulnerability was really exploited. Any hypothetical hacker would not only person to beryllium alert of nan flaw, but would past person to instrumentality their target into sending a web petition complete RDP aliases different postulation that uses larboard 3389. Even if each nan dominos fell, nan hacker could only spot their target's existent IP address, not immoderate of nan existent information they transmitted.
Even if nan threat was small, it's bully to spot ExpressVPN responding proactively to flaws successful its merchandise — bug bounties are great, but a information merchandise should protect its users pinch arsenic galore safeguards arsenic possible. In summation to closing this vulnerability, they're besides adding automated tests that cheque for debug codification accidentally near successful accumulation builds. This, positive a successful independent privateness audit earlier successful 2025, gives nan beardown belief of a supplier that's connected apical of things.
If you bargain thing done a nexus successful this article, we whitethorn gain commission.