QID 92049

Date Published: 2023-08-09

QID 92049: Microsoft Windows Codecs Library HEVC Video Extensions Remote Code Execution (RCE) Vulnerability for August 2023

A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory.

Affected Product:
HEVC Video Extensions before 2.0.61931.0
HEVC Video Extensions before 2.0.61933.0
QID detection Logic:
The gets the version of HEVCVideoExtension and AV1VideoExtension by querying wmi class Win32_InstalledStoreProgram.

An attacker who successfully exploited this vulnerability can compromise confidentiality, integrity and availability of the system

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Users are advised to check CVE-2023-38170

    CVEs related to QID 92049

    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-38170 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38170