• Another HEVC codec bug fixed via the Microsoft Store – plus a couple of updates on this month’s mayhem

    Home » Forums » Newsletter and Homepage topics » Another HEVC codec bug fixed via the Microsoft Store – plus a couple of updates on this month’s mayhem

    Author
    Topic
    #2304640

    Back in July I wrote about two weird Microsoft Store patches for a couple of security holes in the HEVC codecs, which are programs that Microsoft crea
    [See the full post at: Another HEVC codec bug fixed via the Microsoft Store – plus a couple of updates on this month’s mayhem]

    1 user thanked author for this post.
    Viewing 2 reply threads
    Author
    Replies
    • #2304646

      Microsoft updates :

      * CVE-2020-16898

      – CVE-2020-16898 | Windows TCP/IP Remote Code Execution Vulnerability
      https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-16898

      – Version: 1.1
      – Reason for Revision: The following changes have been made to further clarify the
      information for this vulnerability: 1) Added FAQ and Mitigation sections 2) Added
      Impact of Workaround to the Workaround section 3) Corrected the CVSS score to 8.8
      4) Corrected the Exploitability Index from “1 – Exploitation More Likely” to
      “2 – Exploitation Less Likely”.
      These are informational changes only.
      – Originally October 13, 2020
      – Updated: October 15, 2020
      – Aggregate CVE Severity Rating: Critical

      • This reply was modified 4 years, 4 months ago by Alex5723.
      1 user thanked author for this post.
    • #2304644

      So unless you’ve specifically downloaded the Microsoft codec, you don’t need to worry about it – but be aware that this one is also coming through Windows Update.

      Like last time; this update is via Microsoft Store, not Windows Update:

      Why are these security updates offered to affected clients via the Microsoft Store and not Windows Update?
      These updates are for optional apps/components that are offered to customers as a download via the Microsoft Store. Updates for optional store apps/components are provided via the Microsoft Store.
      CVE-2020-17022 | Microsoft Windows Codecs Library Remote Code Execution Vulnerability FAQ

      But also like last time, “Get updates” in Microsoft Store produced nothing for me. So I used this store link again which did download/install the correct update:

      https://www.microsoft.com/en-us/p/hevc-video-extensions-from-device-manufacturer/9n4wgh0z6vhq

      1 user thanked author for this post.
      • #2304701

        Like last time; this update is via Microsoft Store, not Windows Update

        You’re absolutely right. I changed the main post.

      • #2304880

        But also like last time, “Get updates” in Microsoft Store produced nothing for me. So I used this store link again which did download/install the correct update: ….

        On one of my Windows 10 devices, version 1909, I have the app HEVC Video  Extensions for Device Manufacturer v 1.0.32022.0 showing in Apps and Features, installed 08/07/2020.  For me, also, right now “Get updates” in Microsoft Store produced nothing.  I also did a search for “HEVC Video Extensions from Device Manufacturer” and nothing came up.

        Then, I went to the link and it said “HEVC Video Extensions from Device Manufacturer is currently not available”.

        What gives here, anyway??

        HEVC-Video-Extensions

        • #2304885

          For me, also, right now “Get updates” in Microsoft Store produced nothing. I also did a search for “HEVC Video Extensions from Device Manufacturer” and nothing came up

          I just now signed into my MS account and clicked “Get updates.”  HEVC Video Extensions from Device Manufacturer then downloaded–v 1.0.32762.0

           

           

    • #2304804

      I found it strange then and still do now, that a patch was released via the MSFT Store…hey it’s Microsoft!
      Next we will be getting patches via facecloth, twatter and google ploy at this rate 😛

      If debian is good enough for NASA...
    Viewing 2 reply threads
    Reply To: Another HEVC codec bug fixed via the Microsoft Store – plus a couple of updates on this month’s mayhem

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: