Solved Win Sandbox Runs in a Remote Desktop Connection (RDC) Session with RDC OFF - Am I Exposed to RDC's Security Vulnerabilities???


Gordy_Z

New member
Local time
9:26 PM
Posts
3
OS
Win 11
I read that Remote Desktop Connection (RDC) has security issues, including concerns about leaving port 3389 open to the world. I didn't want to harden RDC, don't need it, so turned it off first at Settings/System/Remote Desktop. Then I ensured Control Panel/Advanced System Settings/Remote tab - Remote Assistance/Allow Remote Assistance was off and (in the same tab) Remote Desktop/Don't Allow Remote Connections was on.

Moved on to setting up Win Sandbox, did not see RDC as a prerequisite ( ), turned the Sandbox feature on in Windows, re-booted, started playing with it, and noticed it's in an RDC window - clicking the sandbox's "Connection Information" icon displays this RDC window...
1724710605062.png
In my mind, if Sandbox depends on RDC, and RDC is off, Sandbox shouldn't work, which means RDC is at least partly on. I checked if running Win Sandbox had turned RDC on in the real PC but it hadn't... The real System and Control Panel RDC settings are on the left & the virtual PC's are on the right (Sandbox/Settings/Remote Desktop does nothing when clicked)...
1724701614240.png

Apparently even though RDC is "off," enough of it has been brought online to run Win Sandbox. So the question is, even though RDC is off in Settings and Control Panel, is enough of it up and running that I'm exposed to its various vulnerabilities - do I need to harden it by change the listening port to something other than 3389 etc? OR, are these two Windows functions (RDC and Sandbox) so well integrated that they are only talking to each other deep in Windows and there is no aspect of the RDC exposed to the internet?

Thanks,

Gordy_Z
 
Windows Build/Version
Win 11 Pro Build 22631.3880/Version 23H2

My Computer

System One

  • OS
    Win 11
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo
    CPU
    Intel® Core™ i5-1334U, 12M Cache, up to 4.60 GHz
RDC is only an issue if you remote connect to a pc over the internet.

Using it on a LAN i.e. inside the host OS firewall is no issue.
 

My Computer

System One

  • OS
    Windows 11 Pro + Win11 Canary VM.
    Computer type
    Laptop
    Manufacturer/Model
    ASUS Zenbook 14
    CPU
    I9 13th gen i9-13900H 2.60 GHZ
    Motherboard
    Yep, Laptop has one.
    Memory
    16 GB soldered
    Graphics Card(s)
    Integrated Intel Iris XE
    Sound Card
    Realtek built in
    Monitor(s) Displays
    laptop OLED screen
    Screen Resolution
    2880x1800 touchscreen
    Hard Drives
    1 TB NVME SSD (only weakness is only one slot)
    PSU
    Internal + 65W thunderbolt USB4 charger
    Case
    Yep, got one
    Cooling
    Stella Artois (UK pint cans - 568 ml) - extra cost.
    Keyboard
    Built in UK keybd
    Mouse
    Bluetooth , wireless dongled, wired
    Internet Speed
    900 mbs (ethernet), wifi 6 typical 350-450 mb/s both up and down
    Browser
    Edge
    Antivirus
    Defender
    Other Info
    TPM 2.0, 2xUSB4 thunderbolt, 1xUsb3 (usb a), 1xUsb-c, hdmi out, 3.5 mm audio out/in combo, ASUS backlit trackpad (inc. switchable number pad)

    Macrium Reflect Home V8
    Office 365 Family (6 users each 1TB onedrive space)
    Hyper-V (a vm runs almost as fast as my older laptop)
Thanks for the reply. Unfortunately, not understanding PC intricacies, I'd like to see for myself RDC is off to the outside world. I understand if I remote connect to a PC over the internet my session can be hijacked and by choosing to not remotely connect I can prevent that. But, people seemed to be concerned about more than active RDC sessions... "Never ever expose RDP directly to the internet." And I think I know that in a worse case scenario in which someone has my credentials they can log in remotely without me initiating the connection, right?

The Sandbox turned parts of RDC on even though I'd turned it off as shown above. So I'd like to verify/see for myself that it's not turned on enough to include connections beyond my PC and the Sandbox inside it, so that even if they had my credentials they couldn't use my RDC. Cereberus mentioned the Firewall so I looked into mine...

1724861159331.png No Remote anything apps have either Private or Public checked.

I think this shows that my PC's RDC (and remote anything) simply cannot send anything to the web and nothing from the web can reach my PC via RDC, even if they had my RDC sign-in credentials. Is that right?

Thanks again,
 
Last edited:

My Computer

System One

  • OS
    Win 11
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo
    CPU
    Intel® Core™ i5-1334U, 12M Cache, up to 4.60 GHz
I think this shows that my PC's RDC (and remote anything) cannot send anything to the web and nothing from the web can reach my PC via RDC, even if they had my RDC sign-in credentials. Is that right?

Thanks again,
Right.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro for Workstations
    Computer type
    Laptop
    Manufacturer/Model
    ASUSTeK COMPUTER INC. TUF Gaming FX705GM
    CPU
    2.20 gigahertz Intel i7-8750H Hyper-threaded 12 cores
    Motherboard
    ASUSTeK COMPUTER INC. FX705GM 1.0
    Memory
    24428 Megabytes
    Graphics Card(s)
    Intel(R) UHD Graphics 630 / NVIDIA GeForce GTX 1060
    Sound Card
    Intel(R) Display Audio / Realtek(R) Audio
    Monitor(s) Displays
    Integrated Monitor (17.3"vis)
    Screen Resolution
    FHD 1920X1080 16:9
    Hard Drives
    2 SSD SATA/NVM Express 1.3
    WDS500G2B0A-00SM50 500.1 GB
    WDCSDAPNUW-1002 256 GB
    PSU
    19V DC 6.32 A 120 W
    Cooling
    Dual Fans
    Mouse
    MS Bluetooth
    Internet Speed
    Fiber 1GB Cox -us & IGB Orange-fr
    Browser
    Edge Canary- Firefox Nightly-Chrome Dev-Chrome Dev
    Antivirus
    Windows Defender
    Other Info
    VMs of Windows 11 stable/Beta/Dev/Canary
    VM of XeroLinux- Arch based & Debian 13 (Trixie)
  • Operating System
    Windows 11 Insider Canary
    Computer type
    Laptop
    Manufacturer/Model
    ASUS X751BP
    CPU
    AMD Dual Core A6-9220
    Motherboard
    ASUS
    Memory
    8 GB
    Graphics card(s)
    AMD Radeon R5 M420
    Sound Card
    Realtek
    Monitor(s) Displays
    17.3
    Screen Resolution
    1600X900 16:9
    Hard Drives
    1TB 5400RPM
Thanks Oat, you're quick - I think you replied in the first minute before I took it down to edit it (I just put it back up again, maybe it stays up while it's being edited, not sure).

So unless I hear differently I'm going to operate on the assumption that that Firewall capture shows my RDC only operates inside my PC and has no ability to listen for incoming session requests, even if a request has all the right credentials to access RDC on my PC.

Thanks again,
 

My Computer

System One

  • OS
    Win 11
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo
    CPU
    Intel® Core™ i5-1334U, 12M Cache, up to 4.60 GHz
  • Like
Reactions: OAT

Latest Support Threads

Back
Top Bottom