QID 91869

Date Published: 2022-03-09

QID 91869: Microsoft Windows Codecs Library Remote Code Execution (RCE) Vulnerability for March 2022

Multiple security vulnerabilities exist in Microsoft Windows Codecs Library.

Affected Product:
HEIFImageExtension before 1.0.43012.0
VP9VideoExtensions before 1.0.42791.0
RawImageExtension before 2.1.30391.0
HEVCVideoExtension before 1.0.50361.0 and 1.0.50362.0
QID detection Logic:
Detection gets the version of Microsoft.VP9VideoExtension, Microsoft.HEIFImageExtension, Microsoft.RawImageExtension, HEVCVideoExtension by querying wmi class Win32_InstalledStoreProgram.

An attacker who successfully exploited the vulnerability could execute arbitrary code.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Users are advised to check CVE-2022-23300
    Users are advised to check CVE-2022-23295
    Users are advised to check CVE-2022-22007
    Users are advised to check CVE-2022-23301
    Users are advised to check CVE-2022-24451
    Users are advised to check CVE-2022-24452
    Users are advised to check CVE-2022-24453
    Users are advised to check CVE-2022-24457
    Users are advised to check CVE-2022-22006
    Users are advised to check CVE-2022-24501
    Users are advised to check CVE-2022-24456
    Software Advisories
    Advisory ID Software Component Link
    CVE-2022-22006 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22006
    CVE-2022-22007 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23307
    CVE-2022-23295 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23295
    CVE-2022-23300 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23300
    CVE-2022-23301 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23301
    CVE-2022-24451 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24451
    CVE-2022-24452 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24452
    CVE-2022-24453 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24453
    CVE-2022-24456 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24456
    CVE-2022-24457 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24457
    CVE-2022-24501 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24501