Although there is nothing in the specification to prevent automatic logons with empty passwords, this is not a secure default. The autologon flag INFO_AUTOLOGON ([MS-RDPBCGR] 2.2.1.11.1.1) is now ignored for empty passwords.