QID 91869
Date Published: 2022-03-09
QID 91869: Microsoft Windows Codecs Library Remote Code Execution (RCE) Vulnerability for March 2022
Multiple security vulnerabilities exist in Microsoft Windows Codecs Library.
Affected Product:
HEIFImageExtension before 1.0.43012.0
VP9VideoExtensions before 1.0.42791.0
RawImageExtension before 2.1.30391.0
HEVCVideoExtension before 1.0.50361.0 and 1.0.50362.0
QID detection Logic:
Detection gets the version of Microsoft.VP9VideoExtension, Microsoft.HEIFImageExtension, Microsoft.RawImageExtension, HEVCVideoExtension by querying wmi class Win32_InstalledStoreProgram.
An attacker who successfully exploited the vulnerability could execute arbitrary code.
Solution
Users are advised to check CVE-2022-23300
Users are advised to check CVE-2022-23295
Users are advised to check CVE-2022-22007
Users are advised to check CVE-2022-23301
Users are advised to check CVE-2022-24451
Users are advised to check CVE-2022-24452
Users are advised to check CVE-2022-24453
Users are advised to check CVE-2022-24457
Users are advised to check CVE-2022-22006
Users are advised to check CVE-2022-24501
Users are advised to check CVE-2022-24456
Users are advised to check CVE-2022-23295
Users are advised to check CVE-2022-22007
Users are advised to check CVE-2022-23301
Users are advised to check CVE-2022-24451
Users are advised to check CVE-2022-24452
Users are advised to check CVE-2022-24453
Users are advised to check CVE-2022-24457
Users are advised to check CVE-2022-22006
Users are advised to check CVE-2022-24501
Users are advised to check CVE-2022-24456
Vendor References
- CVE-2022-22006 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22006 - CVE-2022-22007 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22007 - CVE-2022-23295 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23295 - CVE-2022-23300 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23300 - CVE-2022-23301 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23301 - CVE-2022-24451 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24451 - CVE-2022-24452 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24452 - CVE-2022-24453 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24453 - CVE-2022-24456 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24456 - CVE-2022-24457 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24457 - CVE-2022-24501 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24501
CVEs related to QID 91869
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-22006 |
|
||
| CVE-2022-22007 |
|
||
| CVE-2022-23295 |
|
||
| CVE-2022-23300 |
|
||
| CVE-2022-23301 |
|
||
| CVE-2022-24451 |
|
||
| CVE-2022-24452 |
|
||
| CVE-2022-24453 |
|
||
| CVE-2022-24456 |
|
||
| CVE-2022-24457 |
|
||
| CVE-2022-24501 |
|