A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1032, CVE-2020-1036, CVE-2020-1041, CVE-2020-1042, CVE-2020-1043.
Monitor this advisory for an available fix and review any installs of the affected package.
Local check
hol-guard supply-chain scanCVE Program Container affects Microsoft/Windows Server (generic). Severity is high. This vulnerability is known to be exploited in the wild. A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1032, CVE-2020-1036, CVE-2020-1041, CVE-2020-1042, CVE-2020-1043.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Microsoft/Windows Servergeneric | 2016 || 2016 (Core installation) || 2008 R2 for x64-based Systems Service Pack 1 || 2008 R2 for x64-based Systems Service Pack 1 (Core installation) || 2012 || 2012 (Core installation) || 2012 R2 || 2012 R2 (Core installation) |
A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1032, CVE-2020-1036, CVE-2020-1041, CVE-2020-1042, CVE-2020-1043.
Monitor this advisory for an available fix and review any installs of the affected package.
Local check
hol-guard supply-chain scanCVE Program Container affects Microsoft/Windows Server (generic). Severity is high. This vulnerability is known to be exploited in the wild. A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1032, CVE-2020-1036, CVE-2020-1041, CVE-2020-1042, CVE-2020-1043.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Microsoft/Windows Servergeneric | 2016 || 2016 (Core installation) || 2008 R2 for x64-based Systems Service Pack 1 || 2008 R2 for x64-based Systems Service Pack 1 (Core installation) || 2012 || 2012 (Core installation) || 2012 R2 || 2012 R2 (Core installation) |
| Not reported |
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Not reported |
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard