Executive brief
Microsoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability where the host server fails to properly validate input from an authenticated user on a guest operating system. Successful exploitation allows an attacker to escape the guest VM and execute arbitrary code on the host operating system.
Affected products
- Microsoft Windows Server 2008 R2 x64
- Microsoft Windows Server 2012
- Microsoft Windows Server 2012 R2
- Microsoft Windows Server 2016
Timeline
- 2020-07-14: disclosed: NVD Published Date
- 2020-07-14: patched: MSRC advisory and patch released
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Confirmed exploited in the wild per CISA KEV entry