๐Ÿ” CVE Alert

CVE-2020-37129

CRITICAL 9.8

Memu Play 7.1.3 - Insecure Folder Permissions

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

Memu Play 7.1.3 contains an insecure folder permissions vulnerability that allows low-privileged users to modify the MemuService.exe executable. Attackers can replace the service executable with a malicious file during system restart to gain SYSTEM-level privileges by exploiting unrestricted file modification permissions.

CWE CWE-276
Vendor microvirt
Product memu play
Published Feb 5, 2026
Last Updated Mar 5, 2026
Stay Ahead of the Next One

Get instant alerts for microvirt memu play

Be the first to know when new critical vulnerabilities affecting microvirt memu play are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Microvirt / Memu Play
7.1.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
exploit-db.com: https://www.exploit-db.com/exploits/48283 memuplay.com: https://www.memuplay.com/ vulncheck.com: https://www.vulncheck.com/advisories/memu-play-insecure-folder-permissions

Credits

chuyreds