In my monthly patch roundup, I kvetched about the bizarre (unprecedented?) security patches MS decided to distribute through the Microsoft Store. The
[See the full post at: Those two weird Microsoft Store fixes for Windows security flaws keep getting stranger]
![]() |
Patch reliability is unclear, but widespread attacks make patching prudent. Go ahead and patch, but watch out for potential problems. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Those two weird Microsoft Store fixes for Windows security flaws keep getting stranger
Home » Forums » Newsletter and Homepage topics » Those two weird Microsoft Store fixes for Windows security flaws keep getting stranger
- This topic has 15 replies, 10 voices, and was last updated 4 years, 9 months ago by
anonymous.
AuthorTopicwoody
ManagerJuly 4, 2020 at 7:50 am #2277636Viewing 7 reply threadsAuthorReplies-
BobT
AskWoody Lounger -
lurks about
AskWoody LoungerJuly 4, 2020 at 9:05 am #2277650MS used to have 1 method for updating Windows. It was relatively straightforward and manageable. All relevant updates showed up in one place. Now I think I have seen 3 different update methods recently for Windows. This is not straightforward nor manageable as now one has to be able to use these methods and worse know what updates in each channel are needed for your system.
-
woody
Manager
-
-
anonymous
GuestJuly 4, 2020 at 11:10 am #2277681I had “HEVC Video Extensions from Device Manufacturer” listed as installed at Settings, Apps.
It was a vulnerable version 1.0.31053.0 which I believe was installed from Microsoft Store a couple of years ago after I read an article like this one which said it was freely available (but only via a Store link as it doesn’t get shown in search results):
How to View HEVC or HEIC Files in Windows 10 for FreeI tried “Get updates” in the Store numerous times but an update was never found.
Eventually I was able to update to the secure version 1.0.31823.0 by reinstalling from the Store by using this link:
https://www.microsoft.com/en-us/p/hevc-video-extensions-from-device-manufacturer/9n4wgh0z6vhq
1 user thanked author for this post.
tcc089
AskWoody PlusJuly 4, 2020 at 11:43 am #2277690So if I may ask @sb or @woody … if the HVEC codec (v1.0.31053.0 in my 1909 installation) has been installed (behind the scenes and unbeknownst to me) by running a normal update from one Win 10 version to another (e.g. 1803 to 1909), is it recommended that we try to update this codec via the Windows Store at this time … or await further information/direction from MS?
Happy 4th, and many thanks!
anonymous
GuestJuly 4, 2020 at 1:56 pm #2277703Mine updated to 1.0.31823.0 without any problems on June 30th. Maybe microsoft should just get out of the business of shipping codecs. I would never use built-in codecs to watch videos; the only reason I installed the HEVC pack was to use with Microsoft ICE, which can work with Media Foundation codecs but unfortunately not with direct show ones.
Cameochi
AskWoody LoungerJuly 5, 2020 at 8:46 am #2277802I discovered another weird Microsoft issue this morning. It is harmless but what the blazes is wrong with Microsoft?? I have Windows 10 Pro and automatic updates are blocked since Microsoft installed the server version instead of the desktop version of an update last November. Today, I found updates installed on 07/03/20. I did not approve them. It gets even weirder because they are installed in my Stardock Start 10 folder which is located in my user files under appdata roaming. The July 3rd update is to fix the supposed Microsoft Store HEVC mess. I have no idea how it got on my machine but it’s fixed?? That is interesting because I do not use the Microsoft Store at all. Why? Because my trust in Microsoft is at about a minus 50 after the mess they made last November. I’ve been into computers since 1964 and I have never seen anything like the mess Microsoft has made with Windows 8 and now with Windows 10. Nothing seems to stop them making one mess after another.
-
This reply was modified 4 years, 10 months ago by
Cameochi.
-
geekdom
AskWoody_MVPJuly 5, 2020 at 9:17 am #2277804If you have Microsoft Store on your machine, those updates will automatically install. Microsoft Store usage is not the qualifying condition.
On permanent hiatus {with backup and coffee}
offline▸ Win10Pro 2004.19041.572 x64 i3-3220 RAM8GB HDD Firefox83.0b3 WindowsDefender
offline▸ Acer TravelMate P215-52 RAM8GB Win11Pro 22H2.22621.1265 x64 i5-10210U SSD Firefox106.0 MicrosoftDefender
online▸ Win11Pro 22H2.22621.1992 x64 i5-9400 RAM16GB HDD Firefox116.0b3 MicrosoftDefender -
PKCano
Manager -
tcc089
AskWoody PlusJuly 7, 2020 at 6:24 pm #2278408Hmm, I have the MS Store “(…) menu\Settings\App updates\Update apps automatically” switched on, and I haven’t received any update to this HVEC codec as yet. I guess if I wait long enough, MS will get round to me.
As in my last post #2277690 in this thread, I would love to hear advice from @sb or @woody or another member of the team, as to what to do, and when.
Thanks again.
-
This reply was modified 4 years, 9 months ago by
tcc089.
-
This reply was modified 4 years, 9 months ago by
-
-
Carl
AskWoody PlusJuly 5, 2020 at 1:07 pm #2277847There’s been some misinformation/confusion surrounding this security update (understatement /s).
1) As far as I can determine, the HEVC codec (aka H.265) no longer exists in a default Windows installation (since 1709 Fall Creators Update). Likely due to HVEC royalty/licensing issues, Microsoft supports the competing royalty-free AV1 coding format which was finalized in March 2018.
2) The (optional) HEVC codec is available in the MS Store for 99 cents. However, there is a free download link intended for developers. See post above.
3) With this codec installed, H.265 videos can be displayed with Windows Media Player (wmplayer) and the Movies & TV app.
4) Even though a codec is NOT an “app”, Microsoft chose to distribute the update via the MS Store presumably because this is where users obtained this particular codec pack and it is listed under “Windows Settings” -> “Apps & features”. I don’t agree, but ….
5) Some 3rd party applications that support H.265 include VLC media player, Handbrake, and ffmpeg. As far as I can tell, these are not impacted because they rely on different codec packages/libraries (either the open source x265 or Kvazaar HEVC).
Could someone who has not installed HVEC from the MS store check whether or not they can display H.265 videos using Media Player? You can test Windows/hardware HVEC support by downloading some small H.265 video test files from here:
Some sources for HEVC codecs other than Microsoft:
x265 HEVC encoder (GNU GPL)
Kvazaar HEVC encoder (academic)More information:
Wikipedia: High Efficiency Video Coding
VLC Security BulletinsAlex5723
AskWoody PlusJuly 6, 2020 at 2:48 pm #2278051H.266/VVC codec released as successor to H.265/HEVC
After devoting several years to its research and standardization, Fraunhofer HHI (together with partners from industry including Apple, Ericsson, Intel, Huawei, Microsoft, Qualcomm, and Sony) is celebrating the release and official adoption of the new global video coding standard H.266/Versatile Video Coding (VVC). This new standard offers improved compression, which reduces data requirements by around 50% of the bit rate relative to the previous standard H.265/High Efficiency Video Coding (HEVC) without compromising visual quality. In other words, H.266/VVC offers faster video transmission for equal perceptual quality. Overall, H.266/VVC provides efficient transmission and storage of all video resolutions from SD to HD up to 4K and 8K, while supporting high dynamic range video and omnidirectional 360° video.
anonymous
GuestJuly 8, 2020 at 2:21 pm #2278637I’m seeing these codecs installed in a large number of Dell Optiplex PCs which were freshly installed last October. The PCs have Intel video chipsets with HEVC hardware decoding support, so the codecs are probably specially licensed by Intel or Dell and Dell included them in their base image.
Because the codecs require royalties, Microsoft may not distribute them via generally available channels like Windows Update, even for security reasons. I would speculate that the Microsoft Store has some kind of entitlement checking built in to it, or Dell provided some kind of license with the original package.
Like all AppX packages, the codecs are installed on a per-userprofile basis. The good news is that if any one user installs an update, the package is staged to install on login for any other user. The bad news is that despite what Microsoft says, the package (for me) requires manually checking for updates in the app store.
I have been unable to find a way to non-interactively run Store updates or install the packages manually. However you can check for vulnerable packages with Powershell as administrator:
Get-AppXPackage -AllUsers -Name Microsoft.HEVC*
and check the version. Beware: you must check for AllUsers or it won’t search the userprofiles for the package at all.
Viewing 7 reply threads - This topic has 15 replies, 10 voices, and was last updated 4 years, 9 months ago by
-

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Add serial device in Windows 11
by
Theodore Dawson
1 hour, 56 minutes ago -
Windows 11 users reportedly losing data due forced BitLocker encryption
by
Alex5723
2 hours, 55 minutes ago -
Cached credentials is not a new bug
by
Susan Bradley
6 hours, 29 minutes ago -
Win11 24H4 Slow!
by
Bob Bible
6 hours, 40 minutes ago -
Microsoft hiking XBox prices starting today due to Trump’s tariffs
by
Alex5723
3 hours, 51 minutes ago -
Asus adds “movement sensor” to their Graphics cards
by
n0ads
8 hours, 50 minutes ago -
‘Minority Report’ coming to NYC
by
Alex5723
5 hours ago -
Apple notifies new victims of spyware attacks across the world
by
Alex5723
17 hours, 32 minutes ago -
Tracking content block list GONE in Firefox 138
by
Bob99
16 hours, 56 minutes ago -
How do I migrate Password Managers
by
Rush2112
46 minutes ago -
Orb : how fast is my Internet connection
by
Alex5723
2 hours, 35 minutes ago -
Solid color background slows Windows 7 login
by
Alex5723
1 day, 5 hours ago -
Windows 11, version 24H2 might not download via Windows Server Updates Services
by
Alex5723
1 day, 3 hours ago -
Security fixes for Firefox
by
Susan Bradley
4 hours, 10 minutes ago -
Notice on termination of services of LG Mobile Phone Software Updates
by
Alex5723
1 day, 15 hours ago -
Update your Apple Devices Wormable Zero-Click Remote Code Execution in AirPlay..
by
Alex5723
2 days, 1 hour ago -
Amazon denies it had plans to be clear about consumer tariff costs
by
Alex5723
1 day, 16 hours ago -
Return of the brain dead FF sidebar
by
EricB
1 day, 3 hours ago -
Windows Settings Managed by your Organization
by
WSDavidO61
6 hours, 14 minutes ago -
Securing Laptop for Trustee Administrattor
by
PeachesP
2 hours, 39 minutes ago -
The local account tax
by
Susan Bradley
1 day, 4 hours ago -
Recall is back with KB5055627(OS Build 26100.3915) Preview
by
Alex5723
2 days, 14 hours ago -
Digital TV Antenna Recommendation
by
Win7and10
2 days, 6 hours ago -
Server 2019 Domain Controllers broken by updates
by
MP Support
3 days, 1 hour ago -
Google won’t remove 3rd party cookies in Chrome as promised
by
Alex5723
3 days, 3 hours ago -
Microsoft Manager Says macOS Is Better Than Windows 11
by
Alex5723
3 days, 6 hours ago -
Outlook (NEW) Getting really Pushy
by
RetiredGeek
2 days, 9 hours ago -
Steps to take before updating to 24H2
by
Susan Bradley
7 hours, 6 minutes ago -
Which Web browser is the most secure for 2025?
by
B. Livingston
2 days, 13 hours ago -
Replacing Skype
by
Peter Deegan
2 days, 2 hours ago
Recent blog posts
Key Links
S | M | T | W | T | F | S |
---|---|---|---|---|---|---|
1 | 2 | 3 | ||||
4 | 5 | 6 | 7 | 8 | 9 | 10 |
11 | 12 | 13 | 14 | 15 | 16 | 17 |
18 | 19 | 20 | 21 | 22 | 23 | 24 |
25 | 26 | 27 | 28 | 29 | 30 | 31 |
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.