← Back to CVE List
Vulnerability Intelligence Report
Microsoft Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability

CVE-2020-1040

A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1032, CVE-2020-1036, CVE-2020-1041, CVE-2020-1042, CVE-2020-1043.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
9.0
CRITICAL
Exploitability:2.3
Impact Score:6.1
EPSS Probability:6.90%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-20 ↗CWE-20 Improper Input Validation

Affected Products & Versions

Vendor Product Affected Versions
Microsoft Windows Server 2016 (affected), 2016 (Core installation) (affected), 2008 R2 for x64-based Systems Service Pack 1 (affected), 2008 R2 for x64-based Systems Service Pack 1 (Core installation) (affected), 2012 (affected), 2012 (Core installation) (affected), 2012 R2 (affected), 2012 R2 (Core installation) (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
6.903%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMicrosoft Corporation · Vendor · USA
Reserved2019-11-04T00:00:00
Published2020-07-14T22:53:58
Last Updated2025-10-21T23:35:39

LINK COPIED TO CLIPBOARD