CRITICAL

CVE-2020-1040

Microsoft Windows Server 2008 2020-07-14 CVSS v3.1
CVSS
9
KEV

Description

A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1032, CVE-2020-1036, CVE-2020-1041, CVE-2020-1042, CVE-2020-1043.

Summary dbcve.org

A remote code execution vulnerability exists in Hyper-V RemoteFX vGPU where the host server fails to properly validate input from an authenticated user on a guest operating system. An attacker who has already authenticated to a guest VM can exploit this to execute arbitrary code on the host with elevated privileges.

Mitigation

Disable RemoteFX vGPU on affected Hyper-V hosts if not required, or apply Microsoft security patches to address the input validation flaw.

Patch Commit

Weakness (CWE)

CWE-20 Improper Input Validation

EPSS Score

7.39%
Probability of exploitation in next 30 days
94.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE