QID 91866

Date Published: 2022-02-09

QID 91866: Microsoft Windows Codecs Library HEVC Video and VP9 Extensions Remote Code Execution (RCE) Vulnerability for February 2022

A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory.

Affected Product:
"HEVC from Device Manufacturer" media codec before version 1.0.43421.0
"VP9 from Device Manufacturer" media codec before version 1.0.42791.0

QID detection Logic:
The gets the version of HEVCVideoExtension and VP9VideoExtensions by querying wmi class Win32_InstalledStoreProgram.

An attacker who successfully exploited this vulnerability can compromise confidentiality, integrity and availability of the system

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Users are advised to check CVE-2022-22709 CVE-2022-21927 CVE-2022-21926 and CVE-2022-21844 for more information.

    CVEs related to QID 91866

    Software Advisories
    Advisory ID Software Component Link
    CVE-2022-21844 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21844
    CVE-2022-21926 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21926
    CVE-2022-21927 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21927
    CVE-2022-22709 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22709