QID 91869

Date Published: 2022-03-09

QID 91869: Microsoft Windows Codecs Library Remote Code Execution (RCE) Vulnerability for March 2022

Multiple security vulnerabilities exist in Microsoft Windows Codecs Library.

Affected Product:
HEIFImageExtension before 1.0.43012.0
VP9VideoExtensions before 1.0.42791.0
RawImageExtension before 2.1.30391.0
HEVCVideoExtension before 1.0.50361.0 and 1.0.50362.0
QID detection Logic:
Detection gets the version of Microsoft.VP9VideoExtension, Microsoft.HEIFImageExtension, Microsoft.RawImageExtension, HEVCVideoExtension by querying wmi class Win32_InstalledStoreProgram.

An attacker who successfully exploited the vulnerability could execute arbitrary code.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Users are advised to check CVE-2022-23300
    Users are advised to check CVE-2022-23295
    Users are advised to check CVE-2022-22007
    Users are advised to check CVE-2022-23301
    Users are advised to check CVE-2022-24451
    Users are advised to check CVE-2022-24452
    Users are advised to check CVE-2022-24453
    Users are advised to check CVE-2022-24457
    Users are advised to check CVE-2022-22006
    Users are advised to check CVE-2022-24501
    Users are advised to check CVE-2022-24456
    Software Advisories
    Advisory ID Software Component Link
    CVE-2022-22006 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22006
    CVE-2022-22007 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23307
    CVE-2022-23295 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23295
    CVE-2022-23300 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23300
    CVE-2022-23301 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23301
    CVE-2022-24451 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24451
    CVE-2022-24452 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24452
    CVE-2022-24453 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24453
    CVE-2022-24456 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24456
    CVE-2022-24457 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24457
    CVE-2022-24501 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24501
    © CVE.report 2026 |

    Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

    CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

    Free CVE JSON API cve.report/api

    CVE.report and Source URL Uptime Status status.cve.report