{"id":16338,"date":"2020-10-17T00:03:00","date_gmt":"2020-10-16T22:03:00","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=16338"},"modified":"2020-11-20T09:39:50","modified_gmt":"2020-11-20T08:39:50","slug":"microsoft-schliet-schwachstelle-cve-2020-17022-in-hevc-codec-library-15-10-2020","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2020\/10\/17\/microsoft-schliet-schwachstelle-cve-2020-17022-in-hevc-codec-library-15-10-2020\/","title":{"rendered":"Microsoft closes vulnerability CVE-2020-17022 in HEVC codec library (10\/15\/2020)"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/win102.jpg\" width=\"58\" height=\"58\" align=\"left\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/?p=236639\" target=\"_blank\" rel=\"noopener noreferrer\">German<\/a>]Microsoft has released a patch to close the RCE vulnerability CVE-2020-17022 in the Windows Codecs Library on October 15, 2020. Because there was some confusion (the vulnerability only affects some Windows 10 users with HVCE codecs) and the patch is coming via the store, I'm pulling this out in a separate blog post.<\/p>\n<p><!--more--><\/p>\n<h2>A warning from German BSI<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg04.met.vgwort.de\/na\/ecd5d933074f4cf18e027f51c245a03b\" alt=\"\" width=\"1\" height=\"1\" \/>I have seen it in a comment within my German blog and in a Facebook post: German Federal Office for Information Security (BSI) has issued a warning that could cause uncertainty. Here is the translated text:<\/p>\n<blockquote><p>\"[Cert Warning] TW-T20-0179 &#8211; Microsoft Windows 10: Vulnerability allows execution of arbitrary code with user privileges<\/p>\n<p>Type of message: Safety note<br \/>\nRisk level 3<br \/>\nMicrosoft Windows 10: Vulnerability allows execution of arbitrary code with<br \/>\nUser rights<\/p>\n<p>16.10.2020__________________________________________________________________________________________<br \/>\nAffected systems:<br \/>\nMicrosoft Windows 10<br \/>\n____________________________________________________________________________________________________<br \/>\nrecommendation:<br \/>\nThe B\u00fcrgerCERT recommends the prompt installation of the<br \/>\nSecurity updates to close the vulnerabilities.<\/p><\/blockquote>\n<p>The BSI has also linked the security advisor <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2020-17022\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2020-17022 | Microsoft Windows Codecs Library Remote Code Execution Vulnerability<\/a> dated October 15. In this comment the person concerned notes that he cannot find any information on the Microsoft site &#8211; and there is no update via Windows Update.<\/p>\n<h2>This is what is behind CVE-2020-17022<\/h2>\n<p>CVE-2020-17022 is a remote code execution (RCE) vulnerability in a Microsoft Windows Codecs Library used in Windows 10. The problem is the management of objects in memory by the Microsoft Windows Codecs Library, which can be exploited to execute code. An attacker could simply send a specially crafted image file (e.g. via email or a web page) to the victim to exploit the vulnerability. He can then execute arbitrary code.<\/p>\n<h3>Don't count on Windows Update<\/h3>\n<p>The vulnerability is managed at a high risk level due to remote code execution. Microsoft has also released appropriate security updates for Windows 10. The BSI recommends to patch &#8211; but the Microsoft security page CVE-2020-17022 does not contain any links to download an update. Nothing can be downloaded via Windows Update either. .<\/p>\n<h3>Only relevant for certain users<\/h3>\n<p>Let's get to the but &#8211; because the topic or the update is only relevant for Windows 10 users who have installed the optional media codecs HEVC or \"HEVC from the device manufacturer\" from the Microsoft Store. Affected users may be at risk, but will get the update automatically from the Microsoft Store. Users do not need to take any action to receive the update. Alternatively, if you want to be sure that you have received the update, you can check for updates using the Microsoft Store App.<\/p>\n<p>Maybe this will help one or the other user &#8211; my phone rang immediately when I read the above comment because I had already read Woody Leonhard's <a href=\"https:\/\/www.askwoody.com\/2020\/another-hevc-codec-bug-fixed-via-the-microsoft-store-plus-a-couple-of-updates-on-this-months-mayhem\/\" target=\"_blank\" rel=\"noopener noreferrer\">note<\/a> on Thursday.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Microsoft has released a patch to close the RCE vulnerability CVE-2020-17022 in the Windows Codecs Library on October 15, 2020. Because there was some confusion (the vulnerability only affects some Windows 10 users with HVCE codecs) and the patch is &hellip; <a href=\"https:\/\/borncity.com\/win\/2020\/10\/17\/microsoft-schliet-schwachstelle-cve-2020-17022-in-hevc-codec-library-15-10-2020\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580,22,2],"tags":[69,195,76],"class_list":["post-16338","post","type-post","status-publish","format-standard","hentry","category-security","category-update","category-windows","tag-security","tag-update","tag-windows-10"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/16338","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=16338"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/16338\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=16338"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=16338"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=16338"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}