Security
Headlines
HeadlinesLatestCVEs

Tag

#microsoft

CVE-2021-38661: HEVC Video Extensions Remote Code Execution Vulnerability

*How do I get the updated app?* The Microsoft Store will automatically update affected customers. Alternatively, customers can get the update immediately; see here for details. It is possible for customers to disable automatic updates for the Microsoft Store. The Microsoft Store will not automatically install this update for those customers. *My system is in a disconnected environment; is it vulnerable?* Customers using the Microsoft Store for Business and Microsoft Store for Education can get this update through their organizations. *How can I check if the update is installed?* If your device manufacturer preinstalled this app, package versions *1.0.42091.0* and later contain this update. If you purchased this app from the Microsoft Store, package versions *1.0.42094.0* and later contain this update. You can check the package version in PowerShell: Get-AppxPackage -Name Microsoft.HEVCVideoExtension*

Microsoft Security Response Center
#Microsoft Windows Codecs Library#Security Vulnerability#vulnerability#microsoft
CVE-2021-38657: Microsoft Office Graphics Component Information Disclosure Vulnerability

*What type of information could be disclosed by this vulnerability?* The type of information that could be disclosed if an attacker successfully exploited this vulnerability is uninitialized memory.

CVE-2021-38644: Microsoft MPEG-2 Video Extension Remote Code Execution Vulnerability

*Is Windows vulnerable in the default configuration?* No. Only customers who have installed this app from the Microsoft Store may be vulnerable. *How do I get the updated app?* The Microsoft Store will automatically update affected customers. Alternatively, customers can get the update immediately; see here for details. It is possible for customers to disable automatic updates for the Microsoft Store. The Microsoft Store will not automatically install this update for those customers. *My system is in a disconnected environment; is it vulnerable?* Customers using the Microsoft Store for Business and Microsoft Store for Education can get this update through their organizations. *How can I check if the update is installed?* App package versions *1.0.42152.0* and later contain this update. You can check the package version in PowerShell: Get-AppxPackage -Name Microsoft.MPEG2VideoExtension