MS.Windows.Camera.Codec.Pack.Remote.Code.Execution

description-logoDescription

This indicates an attack attempt to exploit a Remote Code Execution vulnerability in Microsoft Windows Camera Codec Pack.
This vulnerability is due insufficient handling of maliciously crafted file. A remote attacker may be able to exploit this vulnerability by enticing a user to open a malicious crafted file.

affected-products-logoAffected Products

Windows 10 prior to KB4577049
Windows 10 version 1607 prior to KB4577015
Windows 10 version 1709 prior to KB4577041
Windows 10 version 1803 prior to KB4577032
Windows 10 version 1809 prior to KB4570333
Windows 10 version 1903 prior to KB4574727
Windows 10 version 1909 prior to KB4574727
Windows 10 version 2004 prior to KB4571756
Windows Server 2016 prior to KB4577015
Windows Server 2019 prior to KB4570333
Windows Server version 1903 prior to KB4574727
Windows Server version 1909 prior to KB4574727
Windows Server version 2004 prior to KB4571756

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0997

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2022-09-19 22.396 Default_action:pass:drop
2022-09-08 22.388