QID 91885
Date Published: 2022-04-13
QID 91885: Microsoft HEVC Video Extensions Remote Code Execution (RCE) Vulnerability for April 2022
A remote code execution vulnerability exists in the way that Microsoft Windows Extensions handle objects in memory.
Affected Product:
"HEVC from Device Manufacturer" media codec before version 1.0.50361.0
QID detection Logic:
This gets the version of HEVCVideoExtension by querying WMI class Win32_InstalledStoreProgram.
An attacker who successfully exploited this vulnerability can compromise confidentiality, integrity and availability of the system
Solution
Users are advised to check CVE-2022-24532 for more information.
Vendor References
- CVE-2022-24532 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24532
CVEs related to QID 91885
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-24532 |
|