Typical severity: High. Likelihood of attack: Medium. An adversary exploits the inherent functionalities of a web browser, in order to establish an unnoticed remote desktop connection in the victim's browser to the adversary's system. The adversary must deploy a web client with a remote desktop session that the victim can access.
Implementation: Use strong, mutual authentication to fully authenticate with both ends of any communications channel