CVE-2020-37129: Microvirt Memu Play

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Memu Play 7.1.3 contains an insecure folder permissions vulnerability that allows low-privileged users to modify the MemuService.exe executable. Attackers can replace the service executable with a malicious file during system restart to gain SYSTEM-level privileges by exploiting unrestricted file modification permissions.

Affected products

Published 2026-02-05. Last modified 2026-06-17.