QID 92030

Date Published: 2023-07-12

QID 92030: Microsoft Raw Image Extension and VP9 Video Extension Information Disclosure Vulnerability

Microsoft has disclosed Information Disclosure Vulnerability in Windows VP9 Video Extensions.

Affected Product:
Raw Image Extension Win10 Version 21H2 and 22H2 , Win11 Version 21H2 prior to 2.0.61662.0
Raw Image Extension Win11 Version 22H2 prior to 2.1.61661.0
VP9 Video Extensions prior to 1.0.61591.0
QID detection Logic:
The detection gets the version of VP9VideoExtension by querying wmi class Win32_InstalledStoreProgram.

An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory..

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    Users are advised to check CVE-2023-36872,CVE-2023-32051for more information.

    CVEs related to QID 92030

    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-32051 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32051
    CVE-2023-36872 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36872