EXPOSURES › CVE-2020-1040
CVE-2020-1040
HIGH ⌖ ON CISA KEV · EXPLOITEDMicrosoft Hyper-V RemoteFX vGPU suffered an improper input validation flaw allowing authenticated guest users to execute remote code on the host.
The vulnerability in Microsoft Hyper-V RemoteFX vGPU allowed an authenticated user on a guest OS to bypass input validation and execute arbitrary code on the host system. For DIB organizations, this means virtualized environments hosting sensitive data are vulnerable to compromise if the patch is not applied, directly impacting CMMC/NIST 800-171 controls around system integrity and access control. Organizations must ensure all Hyper-V hosts are patched and monitor for exploitation attempts.
Shame score — A critical remote code execution flaw in a widely deployed virtualization technology that was actively exploited in the wild, demonstrating severe negligence in patch management and input validation.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability due to the host server failing to properly validate input from an authenticated user on a guest operating system. Successful exploitation allows for remote code execution on the host operating system.
"Microsoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability due to the host server failing to properly validate input from an authenticated user on a guest operating system. Successful exploitation allows for remote code execution on the host operating system."
"Microsoft CVEs and Security Vulnerabilities - OpenCVE"
"Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find"
"CISA Adds Three Known Exploited Vulnerabilities to Catalog"
"CVE DB API - Fast Vulnerability Dashboard - Shodan"
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |