Skip to content
COOEY

EXPOSURES › CVE-2020-1040

CVE-2020-1040

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-1040 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Microsoft Hyper-V RemoteFX vGPU suffered an improper input validation flaw allowing authenticated guest users to execute remote code on the host.

The vulnerability in Microsoft Hyper-V RemoteFX vGPU allowed an authenticated user on a guest OS to bypass input validation and execute arbitrary code on the host system. For DIB organizations, this means virtualized environments hosting sensitive data are vulnerable to compromise if the patch is not applied, directly impacting CMMC/NIST 800-171 controls around system integrity and access control. Organizations must ensure all Hyper-V hosts are patched and monitor for exploitation attempts.

Shame score — A critical remote code execution flaw in a widely deployed virtualization technology that was actively exploited in the wild, demonstrating severe negligence in patch management and input validation.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability due to the host server failing to properly validate input from an authenticated user on a guest operating system. Successful exploitation allows for remote code execution on the host operating system.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
Microsoft's Hyper-V RemoteFX vGPU contains an improper input validation vulnerability, allowing for remote code execution on the host operating system. This has been exploited in the wild.
cooey ↗ severe-fallout -1.00
Microsoft Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability
"Microsoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability due to the host server failing to properly validate input from an authenticated user on a guest operating system. Successful exploitation allows for remote code execution on the host operating system."
app.opencve.io ↗ severe-fallout -1.00
Microsoft CVEs and Security Vulnerabilities - OpenCVE
"Microsoft CVEs and Security Vulnerabilities - OpenCVE"
www.cvefind.com ↗ severe-fallout -1.00
Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find
"Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find"
github.com ↗ severe-fallout -1.00
CISA Adds Three Known Exploited Vulnerabilities to Catalog
"CISA Adds Three Known Exploited Vulnerabilities to Catalog"
CISA ↗ severe-fallout -1.00
CVE DB API - Fast Vulnerability Dashboard - Shodan
"CVE DB API - Fast Vulnerability Dashboard - Shodan"
cvedb.shodan.io ↗ severe-fallout -1.00
ICS Advisories | CISA
"ICS Advisories | CISA"
AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized