{"id":14900,"date":"2020-07-01T11:43:20","date_gmt":"2020-07-01T09:43:20","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=14900"},"modified":"2022-11-26T18:59:43","modified_gmt":"2022-11-26T17:59:43","slug":"windows-10-critical-codec-vulnerabilities-patched","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2020\/07\/01\/windows-10-critical-codec-vulnerabilities-patched\/","title":{"rendered":"Windows 10: Critical codec vulnerabilities patched"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/win102.jpg\" width=\"58\" align=\"left\" height=\"58\">[<a href=\"https:\/\/www.borncity.com\/blog\/2020\/07\/01\/windows-10-kritische-codec-schwachstellen-gepatcht\/\" target=\"_blank\" rel=\"noopener noreferrer\">German<\/a>]Microsoft has patched vulnerabilities CVE-2020-1425 and CVE-2020-1457 in the Windows Codecs Library in an emergency update on 30 June 2020. This affects Windows 10 and its Windows Server counterparts. <\/p>\n<p><!--more--><\/p>\n<h2>Security information from Microsoft<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" src=\"https:\/\/vg07.met.vgwort.de\/na\/8e7b8e5c6e464bf0b092a13007bc41f9\" width=\"1\" height=\"1\">I have received the information about the unscheduled security updates from Microsoft by mail. They wrote last night: <\/p>\n<p>***********************************************************************<br \/>Title: Microsoft Security Update Releases<br \/>Issued: June 30, 2020<br \/>***********************************************************************<br \/>Summary<br \/>The following CVEs have undergone a major revision increment:<\/p>\n<p>* CVE-2020-1425<br \/>* CVE-2020-1457<\/p>\n<p>Revision Information:<br \/>=====================<\/p>\n<p>* CVE-2020-1425<\/p>\n<p>&#8211; <a href=\"https:\/\/web.archive.org\/web\/20201101221918\/https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/CVE-2020-1425\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2020-1425<\/a> | Microsoft Windows Codecs Library Remote Code Execution<br \/>&nbsp;&nbsp; Vulnerability&nbsp; <br \/>&#8211; Version: 1.0<br \/>&#8211; Reason for Revision: Information published.<br \/>&#8211; Originally posted: June 30, 2020<br \/>&#8211; Updated: N\/A<br \/>&#8211; Aggregate CVE Severity Rating: Critical<\/p>\n<p>* CVE-2020-1457<\/p>\n<p>&#8211; <a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/CVE-2020-1457\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2020-1457<\/a> | Microsoft Windows Codecs Library Remote Code Execution<br \/>&nbsp;&nbsp; Vulnerability<br \/>&#8211; Version: 1.0<br \/>&#8211; Reason for Revision: Information published.<br \/>&#8211; Originally posted: June 30, 2020<br \/>&#8211; Updated: N\/A<br \/>&#8211; Aggregate CVE Severity Rating: Important<\/p>\n<p>Both CVEs are Remote Code Execution (RCE) vulnerabilities that were considered critical.&nbsp;&nbsp; <\/p>\n<h3>CVE-2020-1425-Windows Codecs Library RCE vulnerability<\/h3>\n<p><a href=\"https:\/\/web.archive.org\/web\/20201101221918\/https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/CVE-2020-1425\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2020-1425<\/a> is a remote code execution (RCE) vulnerability in the Microsoft Windows Codecs Library. The RCE vulnerability is due to the way the Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user's system.<\/p>\n<p>Exploiting the vulnerability requires a program to process a specially crafted image file. An available update fixes the vulnerability in the Microsoft Windows Codecs library. Updates are available from Windows 10 version 1709 to Windows Server 2019. For details see <a href=\"https:\/\/web.archive.org\/web\/20201101221918\/https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/CVE-2020-1425\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2020-1425<\/a>. <\/p>\n<h3>CVE-2020-1457-Windows Codecs Library RCE vulnerability<\/h3>\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/CVE-2020-1457\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2020-1457<\/a> is also a Remote Code Execution (RCE) vulnerability in the Microsoft Windows Codecs Library. The RCE vulnerability is due to the way the Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability by using a prepared image file could remotely execute foreign code. An available update resolves the vulnerability in the Microsoft Windows Codecs Library. Updates are available from Windows 10 version 1709 to Windows Server 2019. Details can be found at <a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/CVE-2020-1457\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2020-1457<\/a>. <\/p>\n<h2>Delivery via the store<\/h2>\n<p>Affected customers will be automatically updated by the Microsoft Store (not via Windows Update) with the necessary updates for the Windows Codecs Library. Users do not need to take any action to obtain the update. Alternatively, customers who want to receive the update immediately can use the Microsoft Store App to check for updates. <\/p>\n<p>Martin Brinkmann from ghacks.net has <a href=\"https:\/\/web.archive.org\/web\/20220621203630\/https:\/\/www.ghacks.net\/2020\/07\/01\/critical-windows-codecs-security-issue-affects-windows-10-and-server\/\" target=\"_blank\" rel=\"noopener noreferrer\">published a screenshot here<\/a> showing the update search in the store. The problem with the whole approach: There is no information which updates are needed. And it's also stupid, that the updates are shipped via store. Martin Brinkmann writes on ghacks.net that he found two entries, HEIF image extensions and HEVC video extensions. I found one of these entries during the update search in the store. So I don't know if it fits either. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Microsoft has patched vulnerabilities CVE-2020-1425 and CVE-2020-1457 in the Windows Codecs Library in an emergency update on 30 June 2020. This affects Windows 10 and its Windows Server counterparts.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580,1547,22,2],"tags":[195,86,76,159],"class_list":["post-14900","post","type-post","status-publish","format-standard","hentry","category-security","category-software","category-update","category-windows","tag-update","tag-vulnerability","tag-windows-10","tag-windows-server"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/14900","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=14900"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/14900\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=14900"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=14900"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=14900"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}