Junglewise Threat Intelligence

CVE-2020-1040: Microsoft Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability

CVE-2020-1040 · Severity: critical · CVSS 9 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Windows Server 2012 R2, Microsoft Windows Server 2012, Microsoft Windows Server 2016. Vendors: Microsoft.

Executive brief

Microsoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability where the host server fails to properly validate input from an authenticated user on a guest operating system. Successful exploitation allows an attacker to escape the guest VM and execute arbitrary code on the host operating system.

Affected products

  • Microsoft Windows Server 2008 R2 x64
  • Microsoft Windows Server 2012
  • Microsoft Windows Server 2012 R2
  • Microsoft Windows Server 2016

Timeline

  • 2020-07-14: disclosed: NVD Published Date
  • 2020-07-14: patched: MSRC advisory and patch released
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Confirmed exploited in the wild per CISA KEV entry