TROYANOSYVIRUS
Back to CVEs

CVE-2020-1040

CRITICALCISA KEV
9.0

Description

A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1032, CVE-2020-1036, CVE-2020-1041, CVE-2020-1042, CVE-2020-1043.

CVE Details

CVSS v3.1 Score9.0
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack VectorADJACENT_NETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published7/14/2020
Last Modified10/29/2025
Sourcekev
Honeypot Sightings0

CISA KEV

VendorMicrosoft
ProductHyper-V RemoteFX
Vulnerability NameMicrosoft Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability
KEV Date Added2021-11-03
Remediation Due Date2022-05-03
Ransomware UseUnknown

Affected Products

microsoft:windows_server_2008microsoft:windows_server_2012microsoft:windows_server_2016

Weaknesses (CWE)

CWE-20CWE-20

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.