PT-2022-2049 · Microsoft · Hevc Video Extensions

Dhanesh Kizhakkinan

·

Published

2022-01-11

·

Updated

2024-11-14

·

CVE-2022-21917

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions HEVC Video Extensions (affected versions not specified)
Description The issue is related to incorrect code generation management in the HEVC Video Extension codec. Exploitation of this issue may allow a remote attacker to execute arbitrary code using a specially crafted request.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Memory Corruption

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01705
CVE-2022-21917

Affected Products

Hevc Video Extensions