QID 91788
Date Published: 2021-07-14
QID 91788: Microsoft Windows Codecs Library High Efficiency Video Coding (HEVC) Video Extensions Remote Code Execution (RCE) Vulnerabilities
A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory.
Affected Product:
"HEVC" or "HEVC from Device Manufacturer" media codec before version 1.0.41483.0
QID detection Logic:
The gets the version of HEVCVideoExtension by querying wmi class Win32_InstalledStoreProgram.
An attacker who successfully exploited this vulnerability can compromise confidentiality, integrity and availability of the system
Solution
Users are advised to check CVE-2021-31947 ,CVE-2021-33775 for more information.
, CVE-2021-33776 for more information.
,CVE-2021-33777 for more information.
,CVE-2021-33778 for more information.
Vendor References
- CVE-2021-31947 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2021-31947 - CVE-2021-33775 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2021-33775 - CVE-2021-33776 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2021-33776 - CVE-2021-33777 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2021-33777 - CVE-2021-33778 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2021-33778
CVEs related to QID 91788
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-31947 |
|
||
| CVE-2021-33775 |
|
||
| CVE-2021-33776 |
|
||
| CVE-2021-33777 |
|
||
| CVE-2021-33778 |
|