CVE-2020-1041 is a critical remote code execution vulnerability in Hyper-V RemoteFX vGPU affecting Microsoft Windows Server 2008, 2012, and 2016. It arises from insufficient input validation by the host server when processing data from an authenticated guest operating system user. With a CVSS score of 9.0, this vulnerability allows an attacker to achieve full compromise (confidentiality, integrity, availability) with low attack complexity over an adjacent network. While there is no known public exploit code or active exploitation (not in KEV), it has garnered significant community discussion and media coverage, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:r2:*:*:*:*:*:x64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.3 Reddit, 0.3 Bluesky, 0.4 Mastodon, and 2.6 GitHub mentions.
The average CVE in this peer group has 0.9 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.