CVE-2020-0637: Microsoft Windows Server 2008

Medium severity, CVSS 6.5. EPSS: 5% chance of exploitation in the next 30 days.

An information disclosure vulnerability exists when Remote Desktop Web Access improperly handles credential information, aka 'Remote Desktop Web Access Information Disclosure Vulnerability'.

Affected products

  • Microsoft Windows Server 2008: version r2 only
  • Microsoft Windows Server 2012: affected versions not specified; version r2 only
  • Microsoft Windows Server 2016: affected versions not specified; version 1909 only
  • Microsoft Windows Server 2019: affected versions not specified

Published 2020-01-14. Last modified 2026-06-17.