CVE-2020-37129: Microvirt Memu Play
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Memu Play 7.1.3 contains an insecure folder permissions vulnerability that allows low-privileged users to modify the MemuService.exe executable. Attackers can replace the service executable with a malicious file during system restart to gain SYSTEM-level privileges by exploiting unrestricted file modification permissions.
Affected products
- Microvirt Memu Play: version 7.1.3 only
Published 2026-02-05. Last modified 2026-06-17.