QID 92015
Date Published: 2023-05-10
QID 92015: Microsoft Windows Codecs Library AV1 Video Extensions Remote Code Execution (RCE) Vulnerability for May 2023
A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory.
Affected Product:
AV1 from Device Manufacturer" media codec before version 1.1.60961.0
QID detection Logic:
The gets the version of AV1VideoExtension by querying wmi class Win32_InstalledStoreProgram.
An attacker who successfully exploited this vulnerability through social engineering, convinces a victim to download and open a specially crafted file from a website which leads to a local attack on their computer.
Solution
Users are advised to check CVE-2023-29340,
CVE-2023-29341 for further details.
Vendor References
- CVE-2023-29340 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-29340 - CVE-2023-29341 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-29341
CVEs related to QID 92015
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-29340 |
|
||
| CVE-2023-29341 |
|