Description
Memu Play 7.1.3 contains an insecure folder permissions vulnerability that allows low-privileged users to modify the MemuService.exe executable. Attackers can replace the service executable with a malicious file during system restart to gain SYSTEM-level privileges by exploiting unrestricted file modification permissions.
Published: 2026-02-05
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 05 Mar 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Microvirt memu
CPEs cpe:2.3:a:microvirt:memu:7.1.3:*:*:*:*:*:*:*
Vendors & Products Microvirt memu

Fri, 06 Feb 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Microvirt
Microvirt memu Play
Vendors & Products Microvirt
Microvirt memu Play

Thu, 05 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 05 Feb 2026 16:30:00 +0000

Type Values Removed Values Added
Description Memu Play 7.1.3 contains an insecure folder permissions vulnerability that allows low-privileged users to modify the MemuService.exe executable. Attackers can replace the service executable with a malicious file during system restart to gain SYSTEM-level privileges by exploiting unrestricted file modification permissions.
Title Memu Play 7.1.3 - Insecure Folder Permissions
Weaknesses CWE-276
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Microvirt Memu Memu Play
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-03-05T01:28:07.297Z

Reserved: 2026-02-03T16:27:45.305Z

Link: CVE-2020-37129

cve-icon Vulnrichment

Updated: 2026-02-05T21:16:25.315Z

cve-icon NVD

Status : Deferred

Published: 2026-02-05T17:16:07.870

Modified: 2026-04-15T00:35:42.020

Link: CVE-2020-37129

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-06T12:05:30Z

Weaknesses