QID 91775

Date Published: 2021-06-09

QID 91775: Microsoft Windows VP9 Video Extension Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory.
Microsoft has disclosed Information Disclosure and Remote Code Execution in Windows VP9 Video Extensions.

Affected Product:
VP9 Video Extensions prior to version 1.0.41182.0
QID detection Logic:
The detection gets the version of VP9VideoExtension by querying wmi class Win32_InstalledStoreProgram.

An attacker who successfully exploited this vulnerability could execute arbitrary code on the system.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Users are advised to check CVE-2021-31967 for more information.

    CVEs related to QID 91775

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-31967 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2021-31967