QID 91761

Date Published: 2021-04-14

QID 91761: Microsoft Windows Codecs Library and VP9 Video Extensions Multiple Vulnerabilities

A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory.
Microsoft has disclosed Information Disclosure and Remote Code Execution in Windows Codecs Library and VP9 Video Extensions.

Affected Product:
VP9 Video Extensions prior to version 1.0.40631.0
Raw Image Extension prior to version 1.0.40392.0

QID detection Logic:
The gets the version of HEVCVideoExtension by querying wmi class Win32_InstalledStoreProgram.

An attacker who successfully exploited this vulnerability could obtain information to further compromise the user system.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Users are advised to check CVE-2021-26902 for more information.

    CVEs related to QID 91761

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-27079 Windows URL Logo portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2021-27079
    CVE-2021-28317 Windows URL Logo portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2021-28317
    CVE-2021-28464 Windows URL Logo portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2021-28464
    CVE-2021-28466 Windows URL Logo portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2021-28466
    CVE-2021-28468 Windows URL Logo portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2021-28468