CVE-2020-1040
Description
A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1032, CVE-2020-1036, CVE-2020-1041, CVE-2020-1042, CVE-2020-1043.
Summary dbcve.org
A remote code execution vulnerability exists in Hyper-V RemoteFX vGPU where the host server fails to properly validate input from an authenticated user on a guest operating system. An attacker who has already authenticated to a guest VM can exploit this to execute arbitrary code on the host with elevated privileges.
Mitigation
Disable RemoteFX vGPU on affected Hyper-V hosts if not required, or apply Microsoft security patches to address the input validation flaw.