CVE-2021-1643
published 2021-01-12CVE-2021-1643: HEVC Video Extensions Remote Code Execution Vulnerability
PriorityP341high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
3.89%
89.0th percentile
HEVC Video Extensions Remote Code Execution Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | hevc_video_extensions | < 1.0.33242.0 | 1.0.33242.0 |
| microsoft | hevc_video_extensions | — | — |
| msrc | hevc_video_extensions | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3m8h-6gm5-g2hj: HEVC Video Extensions Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1644
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2021-1643 [HIGH] GHSA-3m8h-6gm5-g2hj: HEVC Video Extensions Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1644
HEVC Video Extensions Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1644.
GHSA
GHSA-cwj3-w85q-28g4: HEVC Video Extensions Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1643
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2021-1644 [HIGH] GHSA-cwj3-w85q-28g4: HEVC Video Extensions Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1643
HEVC Video Extensions Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1643.
Microsoft
HEVC Video Extensions Remote Code Execution Vulnerability
vendor_msrc·2021-01-12·CVSS 7.8
CVE-2021-1643 [HIGH] HEVC Video Extensions Remote Code Execution Vulnerability
HEVC Video Extensions Remote Code Execution Vulnerability
FAQ: How do I get the updated app?
The Microsoft Store will automatically update affected customers. Alternatively, customers can get the update immediately; see here for details.
It is possible for customers to disable automatic updates for the Microsoft Store. The Microsoft Store will not automatically install this update for those customers.
My system is in a disconnected environment; is it vulnerable?
Customers using the Microsoft Store for Business and Microsoft Store for Education can get this update through their organizations.
How can I check if the update is installed?
If your device manufacturer preinstalled this app, package versions 1.0.33242.0 and later contain this update.
If you purchased this app from the Microsoft
No detection rules found.
No public exploits indexed.
Trendmicro
January Patch Tuesday Repairs Critical MS Defender RCE Bug
blogs_trendmicro·2021-01-13·CVSS 7.8
[HIGH] January Patch Tuesday Repairs Critical MS Defender RCE Bug
Exploits & Vulnerabilities
# January Patch Tuesday Repairs Critical MS Defender RCE Bug
Microsoft welcomed the first month of 2021 with a total of 83 security updates — which is an uptick from December’s relatively lighter list.
By: Trend Micro
2021/01/13
Read time: ( words)
Save to Folio
Updated on 1/14/2021 7 p.m. PST to include TippingPoint® Next-Generation Intrusion Prevention System (NGIPS) Protection rules.
Microsoft welcomed the first month of 2021 with a total of 83 security updates — which is an uptick from December’s relatively lighter list. The January Patch Tuesday features 10 Critical and 73 Important patches. All of this month’s Critical patches are meant to fix remote code execution (RCE) vulnerabilities among certain Microsoft products, including Microsoft Defender,
Talos
Microsoft Patch Tuesday for Jan. 2021 — Snort rules and prominent vulnerabilities
blogs_talos·2021-01-12·CVSS 7.8
[HIGH] Microsoft Patch Tuesday for Jan. 2021 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for Jan. 2021 — Snort rules and prominent vulnerabilities
By Jon Munshaw, with contributions from Asheer Malhotra.
Microsoft released its monthly security update Tuesday, disclosing 83 vulnerabilities across its suite of products to kick-off 2021.
There are only 10 critical vulnerabilities as part of this release, while there are two moderate-severity exploits, and the remainder is considered “important.” Users of all Microsoft and Windows products are urged to update their software as soon as possible to avoid possible exploitation of all these bugs.
The security updates cover several different products and services, including the Microsoft Defender antivirus software, the Microsoft Remote Procedure Call tools and Bluetooth communication with Windows devices
Talos
Microsoft Patch Tuesday for Jan. 2021 — Snort rules and prominent vulnerabilities
blogs_talos·2021-01-12·CVSS 7.8
[HIGH] Microsoft Patch Tuesday for Jan. 2021 — Snort rules and prominent vulnerabilities
By Jon Munshaw, with contributions from Asheer Malhotra.
Microsoft released its monthly security update Tuesday, disclosing 83 vulnerabilities across its suite of products to kick-off 2021.
There are only 10 critical vulnerabilities as part of this release, while there are two moderate-severity exploits, and the remainder is considered “important.” Users of all Microsoft and Windows products are urged to update their software as soon as possible to avoid possible exploitation of all these bugs.
The security updates cover several different products and services, including the Microsoft Defender antivirus software, the Microsoft Remote Procedure Call tools and Bluetooth communication with Windows devices. Talos also released a new set of SNORTⓇ rules that provide coverage for some of thes
2021-01-12
Published