PT-2020-3000 · Microsoft · Windows Codecs Library

Published

2020-06-30

·

Updated

2023-11-13

·

CVE-2020-1425

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows Codecs Library (affected versions not specified)
Description A remote code execution issue exists due to errors in handling objects in memory within the Microsoft Windows Codecs Library. This can be exploited by an attacker to execute arbitrary code using a specially crafted image file. The vulnerability is related to the handling of media content and can lead to information disclosure and remote code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2020-03222
BDU:2020-03614
CVE-2020-1425
ZDI-20-802
ZDI-20-804
ZDI-20-815
ZDI-20-816
ZDI-20-817
ZDI-20-818
ZDI-20-819

Affected Products

Windows Codecs Library