QID 91919
Date Published: 2022-06-15
QID 91919: Microsoft Windows Codecs Library HEVC Video and AV1 Extensions Remote Code Execution (RCE) Vulnerability for June 2022
A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory.
Affected Product:
"HEVC from Device Manufacturer" media codec before version 2.0.51121.0
"AV1 from Device Manufacturer" media codec before version 1.1.51091.0
QID detection Logic:
The gets the version of HEVCVideoExtension and AV1VideoExtension by querying wmi class Win32_InstalledStoreProgram.
An attacker who successfully exploited this vulnerability can compromise confidentiality, integrity and availability of the system
Solution
Users are advised to check CVE-2022-30188, CVE-2022-30167, CVE-2022-29119, CVE-2022-29111 and CVE-2022-22018, CVE-2022-30193 for more information.
Vendor References
- CVE-2022-22018 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22018 - CVE-2022-29111 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-29111 - CVE-2022-29119 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-29119 - CVE-2022-30167 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30167 - CVE-2022-30188 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30188 - CVE-2022-30193 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30193
CVEs related to QID 91919
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-22018 |
|
||
| CVE-2022-29111 |
|
||
| CVE-2022-29119 |
|
||
| CVE-2022-30167 |
|
||
| CVE-2022-30188 |
|
||
| CVE-2022-30193 |
|