This could be leveraged to gain RCE on the *client*: https://research.checkpoint.com/reverse-rdp-attack-code-execution-on-rdp-clients/