CVE-2020-1040
KEVlargeGuest-to-Host RCE in Microsoft Hyper-V RemoteFX vGPU on Windows Server
CISA: Microsoft Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability
CVE-2020-1040 is a critical (CVSS 3.1: 9.0) remote code execution flaw in the Hyper-V RemoteFX vGPU component, where the host server fails to properly validate input from an authenticated user on a guest operating system. An attacker who can authenticate to a guest VM configured with a RemoteFX vGPU can send crafted input to the virtual GPU and execute code on the host, achieving a guest-to-host escape with high impact to confidentiality, integrity and availability (scope changed). Only Hyper-V hosts running Windows Server 2008, 2012 or 2016 with the RemoteFX vGPU feature enabled and VMs using RemoteFX 3D video are affected. It is one of five related RemoteFX vGPU vulnerabilities (CVE-2020-1032, 1036, 1041, 1042, 1043) fixed in Microsoft's July 2020 security updates, a release that addressed 123 vulnerabilities and drew attention to RemoteFX issues on AMD and Intel-based systems. CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, indicating exploitation in the wild; EPSS estimates a 7.3% chance of exploitation within 30 days (94th percentile), while no public proof-of-concept is known.
What to do: Apply Microsoft's July 2020 or later security updates to all Hyper-V hosts running Windows Server 2008, 2012 or 2016 with RemoteFX vGPU, per the CISA KEV required action. Until patched, remove the RemoteFX 3D video adapter from guest VMs or disable RemoteFX on the host, and inventory the environment for VMs with RemoteFX vGPU attached. Restrict which users can log on to vGPU-enabled guests, since exploitation requires an authenticated guest user.
| microsoft Windows Server 2008 (Hyper-V with RemoteFX vGPU enabled) | unpatched releases; fixed by the July 2020 security updates |
| microsoft Windows Server 2012 (Hyper-V with RemoteFX vGPU enabled) | unpatched releases; fixed by the July 2020 security updates |
| microsoft Windows Server 2016 (Hyper-V with RemoteFX vGPU enabled) | unpatched releases; fixed by the July 2020 security updates |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1032, CVE-2020-1036, CVE-2020-1041, CVE-2020-1042, CVE-2020-1043.
- Affected
- Microsoft Hyper-V RemoteFX
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows server 2008, windows server 2012, windows server 2016
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H