Microsoft Remote Desktop Web Access CVE-2020-0637 Information Disclosure Vulnerability

description-logoDescription

An information disclosure vulnerability exists when Remote Desktop Web Access improperly handles credential information. An attacker who successfully exploited this vulnerability could obtain legitimate users' credentials. To exploit this vulnerability, an attacker would need access to a vulnerable server with the Remote Desktop Web Access role. The security update addresses the vulnerability by correcting how Remote Desktop Web Access handles credential information.

affected-products-logoAffected Applications

Windows Server 2016
Windows Server 2008
Windows Server 2012
Windows Server 2019

CVE References

CVE-2020-0637