QID 91946
Date Published: 2022-09-14
QID 91946: Microsoft Windows Codecs Library RawImageExtensions and AV1 Extensions Remote Code Execution (RCE) Vulnerability for September 2022
A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory.
Affected Product:
RawImageExtension from Device Manufacturer" media codec before version 2.0.32061.0
AV1 from Device Manufacturer" media codec before version 1.1.52074.0
QID detection Logic:
The gets the version of AV1VideoExtension by querying wmi class Win32_InstalledStoreProgram.
An attacker who successfully exploited this vulnerability can compromise confidentiality, integrity and availability of the system
Solution
Users are advised to check CVE-2022-38019,
CVE-2022-38011 for further details.
Vendor References
- CVE-2022-38011 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-38011 - CVE-2022-38019 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-38019
CVEs related to QID 91946
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-38011 |
|
||
| CVE-2022-38019 |
|