QID 91855
Date Published: 2022-01-12
QID 91855: Microsoft HEVC Video Extensions Remote Code Execution (RCE) Vulnerability for January 2022
A crafted image file could cause a crash in Explorer during browsing of the directory containing the file.
Affected Product:
"HEVC from Device Manufacturer" media codec before version 1.0.43421.0
QID Detection Logic (Authenticated):
- Checks for vulnerable version of HEVC Video Extensions via wmi_query
This vulnerability would require an authenticated victim to be tricked into opening a specially crafted media file which could result in remote code execution on the victim's machine.
Solution
Users are advised to check CVE-2022-21917 for more information.
Vendor References
- CVE-2022-21917 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21917
CVEs related to QID 91855
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-21917 |
|