This one’s more interesting than the typical Windows zero-day. MS just published a Security Update for CVE-2020-1425 | Microsoft Windows Codecs Librar
[See the full post at: Win10 codec security hole]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Win10 codec security hole
Home » Forums » Newsletter and Homepage topics » Win10 codec security hole
- This topic has 33 replies, 17 voices, and was last updated 4 years, 8 months ago by
anonymous.
Tags: Codec hack. hackers security
AuthorTopicViewing 11 reply threadsAuthorReplies-
OscarCP
MemberJune 30, 2020 at 5:33 pm #2276710Does this bug affects versions of Windows earlier than 10?
Ex-Windows user (Win. 98, XP, 7); since mid-2017 using also macOS. Presently on Monterey 12.15 & sometimes running also Linux (Mint).
MacBook Pro circa mid-2015, 15" display, with 16GB 1600 GHz DDR3 RAM, 1 TB SSD, a Haswell architecture Intel CPU with 4 Cores and 8 Threads model i7-4870HQ @ 2.50GHz.
Intel Iris Pro GPU with Built-in Bus, VRAM 1.5 GB, Display 2880 x 1800 Retina, 24-Bit color.
macOS Monterey; browsers: Waterfox "Current", Vivaldi and (now and then) Chrome; security apps. Intego AV -
PKCano
Manager
-
geekdom
AskWoody_MVPJune 30, 2020 at 6:03 pm #2276715Two out-of-band patches released:
On permanent hiatus {with backup and coffee}
offline▸ Win10Pro 2004.19041.572 x64 i3-3220 RAM8GB HDD Firefox83.0b3 WindowsDefender
offline▸ Acer TravelMate P215-52 RAM8GB Win11Pro 22H2.22621.1265 x64 i5-10210U SSD Firefox106.0 MicrosoftDefender
online▸ Win11Pro 22H2.22621.1992 x64 i5-9400 RAM16GB HDD Firefox116.0b3 MicrosoftDefender1 user thanked author for this post.
-
woody
Manager -
anonymous
GuestJune 30, 2020 at 10:01 pm #2276749Geekdom, good point regarding the out-of-band patches. I was working on a customer’s old Windows 7 Pro 32 bit box to add a FF add on as Admin and it restarted slowly and showing 2 critical updates. The 2 updates were noted in the restore point logs. In his Box’s Your Update history for windows 7 there were only 1 update for KB2310138 which I assume is a Defender or Security Essentials virus definition update. I see his updates are turned off for this old Windows 7 machine and no extended contract.
Remove if this is a dup.
Brocktoon
AskWoody LoungerPerthMike
AskWoody PlusJune 30, 2020 at 7:27 pm #2276734Oh for crying out loud. Now we need to unblock the Store in order to get core OS security updates? FFS, Microsoft. This is why we have WSUS, so we don’t need to phone home to Microsoft (or get a flood of pushed software and bad drivers from the store.
Just the other day I built a new install on a PC, and accidentally left the Store un-blocked for a few minutes. Before I had a chance to even install the vendor drivers, the stupid OS had sucked down all the Store-issued hardware drivers.
No matter where you go, there you are.
-
Carl D
AskWoody LoungerJune 30, 2020 at 11:48 pm #2276768Not sure if it has been discussed here already but a lot of people are annoyed that you now can only get the NVIDIA Control Panel for Windows 10 from the Microsoft Store as well these days. It isn’t included with the drivers.
Huh? Why? My guess is that MS need to do something to get people “interested” in their store. Seems like there’s mainly been tumbleweeds blowing around in there since it opened.
I don’t need the NVIDIA Control Panel – I just want the drivers but I notice a “helpful” message pops up in the bottom right hand corner of the screen every time I install or update the NVIDIA graphics drivers in Windows 10 telling me I can get the Control Panel from the store… “Click Here to get it”. I just ignore it and it goes away.
Oh, the NVIDIA Control Panel is still included in the latest drivers for Windows 7, I notice. Funny about that.
1 user thanked author for this post.
-
anonymous
GuestJuly 1, 2020 at 1:44 am #2276770 -
anonymous
GuestJuly 1, 2020 at 9:02 am #2276867thought it may be helpful to add that you have to click on “Beta and Older Drivers” to get that Advanced Driver Search page…
Took me some time to figure that one out since never in my mind would i click on something called “Beta and Older Drivers” when I want to get hold of a stable up to date released driver.
Seems like many companies are very eager to be number one on my s***list these days.
Anyhow you made me look for it so a thanks is in order, highly appreciated.
-
wavy
AskWoody PlusJuly 1, 2020 at 5:29 pm #2277057They trying to push that but under “NVIDIA>Download Drivers>Advanced Driver Search” select driver type standard and you will have control panel included. DCH are the win store ones.
Is that the same as the studio drivers?
I believe I ended up with the control panel w/o out a MS account on my newis install. its a [pain] to be forced to use the ‘store’ as i did on a previous install🍻
Just because you don't know where you are going doesn't mean any road will get you there. -
Alex5723
AskWoody PlusJuly 2, 2020 at 1:04 am #2277110DCH Game drivers are not the same as Studio drivers.
I download directly from Nvidia and get the control panel.1 user thanked author for this post.
-
anonymous
GuestJuly 2, 2020 at 11:38 am #2277218You linked to the DCH driver, this needs to download the control panel via MS Store on Windows 10. If you think you got it without downloading it via the Store I can only assume it did that automaticly and your settings was set to do so. Either which way, if you do a fresh install the DCH version on a offline machine will not give you the control panel.
You get the none DCH version here, and choose “Standard” version. https://www.nvidia.com/Download/Find.aspx?lang=en-us
(You have to click on “Beta and Older Drivers” on default site to get that Advanced Driver Search page)
1 user thanked author for this post.
-
-
-
-
anonymous
GuestJuly 1, 2020 at 4:30 pm #2277036I’ve got an ASUS Laptop and the Control Software coming from the MS store and what a headache that’s been that’s never got some features working properly. And some UWP app that is the UI/front end device functionality is made functional via some needed service that has to be installed first before the UWP based front end/UI! And that’s not working out so well with that all bundled together and no proper way to assure that the UWP part gets installed after the service part that needs to be instilled first before that UWP front end/UI will work properly.
So a new from of dependency H E Double Toothpicks ensues!
it1
AskWoody PlusJuly 2, 2020 at 3:10 am #2277125Alex5723
AskWoody PlusQuazi11
AskWoody LoungerJuly 1, 2020 at 8:26 am #2276858Building on what Brocktoon stated, that the update was for the HEVC video extension (I can’t confirm). Without much digging you find the video extension does not install by default but must be installed via the store. So, for those of us with the store blocked, we don’t need it because we never installed that app from the store, right? I’ll run this by my TAM, will also be interesting what Qualys comes up with as a detection method. Will report if I find anything.
1 user thanked author for this post.
abbodi86
AskWoody_MVPJuly 1, 2020 at 10:46 am #2276911You don’t need it if you already uninstalled all apps
those who have “some” apps but not the Store, or blocked the Store, can download the updated appx from this site (the download links will be from Microsoft)
https://store.rg-adguard.net/in the left box change URL to PackageFamiliyName, and paste the needed appx PFM
those are the codec-related ones
Microsoft.HEIFImageExtension_8wekyb3d8bbwe
Microsoft.VP9VideoExtensions_8wekyb3d8bbwe
Microsoft.WebpImageExtension_8wekyb3d8bbwepress the check mark button on the right
then download the proper appx file (for x64 system you need both x64 and x86 appx files)
e.g.
Microsoft.HEIFImageExtension_1.0.31572.0_x64__8wekyb3d8bbwe.appx
Microsoft.HEIFImageExtension_1.0.31572.0_x86__8wekyb3d8bbwe.appxyou may need to rename the downloaded files
finally, you can install the updated pacs with double-click (if you still have App Installer)
or via Powershell as administratorAdd-AppxPackage -Path Microsoft.HEIFImageExtension_1.0.31572.0_x64__8wekyb3d8bbwe.appx
-
anonymous
GuestJuly 1, 2020 at 2:39 pm #2276982When I put the product code in I get multiple versions listed. I can’t find info on which exact version I should have to be patched.
Your post says use 1.0.31572.0 but I also get 1.0.31572.70, which I assume I should grab instead, no? Same idea happens for the VP9 codec.I also was only able to install the 64bit version.
Thoughts? Seems odd but I have never done this before. -
abbodi86
AskWoody_MVP
-
rc primak
AskWoody_MVPJuly 1, 2020 at 4:24 pm #2277034What has Windows 10 codec bug to do with Microsoft Store ? I have blocked Microsoft Store and uninstalled all apps too, so no update for me ?
See my Post https://www.askwoody.com/forums/topic/win10-codec-security-hole/#post-2277031 . It’s about patents, royalties and keeping the OS core free of third-party properties.
-- rc primak
-
This reply was modified 4 years, 8 months ago by
rc primak.
CAS
AskWoody PlusJuly 2, 2020 at 8:49 am #2277184Alex, based on your response, I blocked MS store. I was unaware that I could do that before reading what you wrote. Hence the “thank you”.
Using Revo (free) I uninstalled every single remaining MS app that was created when I installed Win 10 as well as any connected entries found by the Revo scan after the uninstall.
Just to be certain that everything was okay, I checked the system image health using DISM and found it healthy and intact. I then ran an sfc scan and found no integrity issues. I rebooted my computer and found everything running just fine. The event viewer showed no issues, yesterday or today.
Admittedly, I’m no computer geek, but I think that I’ve done all I can to protect myself against this latest MS codec fiasco. If anyone still thinks I’m still at risk please let me know. I have backed up system images from last month, before and after the installation of the June updates for 1903 just in case I jumped the gun.
CAS
geekdom
AskWoody_MVPJuly 1, 2020 at 6:46 am #2276845I hope the new means of requiring updates through the Microsoft Store doesn’t become standard practice.
- The update installs invisible and silently.
- The update is not through Windows update which would be the usual place to find updates. This update requires new procedures.
- Not everyone uses Microsoft Store, nor allows it to run. There’s quite a spread between installing Candy Crush and a Windows update.
- Toy and computer operations are now mixed.
On permanent hiatus {with backup and coffee}
offline▸ Win10Pro 2004.19041.572 x64 i3-3220 RAM8GB HDD Firefox83.0b3 WindowsDefender
offline▸ Acer TravelMate P215-52 RAM8GB Win11Pro 22H2.22621.1265 x64 i5-10210U SSD Firefox106.0 MicrosoftDefender
online▸ Win11Pro 22H2.22621.1992 x64 i5-9400 RAM16GB HDD Firefox116.0b3 MicrosoftDefender5 users thanked author for this post.
Carl
AskWoody PlusJuly 1, 2020 at 12:38 pm #2276938I know I may not be the brightest lightbulb in the house, but I find this mess a bit confusing.
1) Are the vulnerable codecs installed by default in Win 10 or do they exist because of something installed by the user (e.g. H2.65)?
2) Are these codecs installed/used by 3rd party applications?
3) For those who use local account only (machine not linked to MS account), will they receive the update?
4) Why is the update not pushed through Win Update?
5) Will the fixes be available in the MS Catalog?Anyway, for anyone interested, while logged into my local account on Win 10 1909, I did the following:
1) Clicked the MS Store icon in the task bar.
2) Click the hamburger in the upper right.
3) Selected “Downloads and updates”.The “HEVC Video Extension” update then downloaded and installed. I’m assuming this is the fix.
CAS
AskWoody PlusJuly 1, 2020 at 12:39 pm #2276939I don’t know whether or not I should be concerned about this issue. I do not ever buy any apps from the MS store. I sign in locally on Win 10 Pro (1909. 18363. 900) and did not establish an MS account when I first installed Win 10. However, after I did the initial install, I disabled Cortana and all permissions for the few apps that I kept and deleted all the rest, including MS Edge. The only MS Apps that remain are:
- HEIF Image Extensions. I use InfranView64 for my photos and VLC player for everything else. I checked and there is a Codec package for this app.
- Get Help. I do not use this at all, ever. That’s what this site is for.
- MS Photos. I do not use this at all, either.
- Tips. As with Help, I do not use this at all. Once again, I come here for tips.
- Voice Recorder. Although I do not use this app, I thought that I might use it some day. Today, I did a search and found several free alternatives.
Revo Uninstaller allows for the complete removal of each of these apps, although I haven’t done it, yet. I kept these apps because I didn’t know what they were or if I would ever need them. I did, however, disable them as well as all permissions that pertain to them. Now, with this issue, I think it’s best that I remove them. Do you agree? (MS settings will not allow me to either terminate or uninstall them?) Should I be concerned about this codec issue once these apps are removed?
CAS
-
This reply was modified 4 years, 8 months ago by
CAS.
-
rc primak
AskWoody_MVP
Carl
AskWoody PlusJuly 1, 2020 at 1:55 pm #2276969Well, it seems I’m not the only one that’s confused. Martin over at ghacks has just expressed similar concerns:
Critical Windows Codecs security issue
Scroll to the bottom of the article and see the section “Lack of information is a problem”.
rc primak
AskWoody_MVPJuly 1, 2020 at 4:16 pm #2277031OK, so here’s my take on why the patch comes via the Store Apps.
Many codecs have patents associated with them. These in turn cost royalties if the OS vendor uses them in North American editions. (In the EU no one charges for codecs, which is why VLC Player includes them in its core program and extensions/plugins.)
Microsoft decided awhile ago not to support codecs for which they would have to pay royalties. This is why Windows 10 does not natively play DVDs. That feature was moved out to the Microsoft Store. It’s also why the codecs and extensions to use the file formats which require the codecs got moved out to the Microsoft Store. So things which got moved out to the MS Store have to be patched via Store App updates. Just as if you had third-party drivers installed, and they would have to be patched through the vendors. (I never accept third-party driver updates offered through MS Updates.)
Driver-related apps, like control panels, have also been moved out to the MS Store, for some of the same reasons. Personally, I don’t mind updating my Realtek and Intel Control Panels this way. They work just as well, whether they are well-buried alternative features inside of Windows 10, or whether they can be fired up from Start Menu Tiles or Taskbar Shortcuts.
I also have the Intel Drivers and Support Assistant and an Epson Printer drivers and firmware updater, both of which operate as separate apps. Same for my Screenbeam WiDi dongle’s updater and settings app. Some are MS Store Apps, some are Win32 Apps. But each one is no longer part of the Windows OS core.
The idea seems to be to move third-party properties outside of the core OS, and only include Microsoft-owned and developed features inside the core OS. It actually makes sense, and is a practice being pursued by Google, Apple, Canonical (Ubuntu Linux) and Red Hat/Fedora Linux. Web browsers seem also to be moving more and more optional features out into extensions.
These changes make updating a hassle, but they keep the core OS less messy to maintain for the core OS developers and maintainers.
-- rc primak
Alex5723
AskWoody PlusJuly 2, 2020 at 12:58 pm #2277266I can only assume it did that automaticly and your settings was set to do so.
Microsoft Store in blocked so no background downloads…
I don’t perform clean install, just update the current version, currently use Studio drivers.-
This reply was modified 4 years, 8 months ago by
Alex5723.
anonymous
GuestViewing 11 reply threads - This topic has 33 replies, 17 voices, and was last updated 4 years, 8 months ago by
-

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Google’s 10-year-old Chromecast is busted, but a fix is coming
by
Alex5723
41 minutes ago -
Expand the taskbar?
by
CWBillow
32 minutes ago -
Gregory Forrest “Woody” Leonhard (1951-2025)
by
Susan Bradley
40 minutes ago -
March 2025 updates are out
by
Susan Bradley
10 hours, 14 minutes ago -
Windows 11 Insider Preview build 26120.3380 released to DEV and BETA
by
joep517
18 hours, 18 minutes ago -
Update Firefox to prevent add-ons issues from root certificate expiration
by
Alex5723
1 day, 1 hour ago -
Latest Firefox requires Password on start up
by
Gordski
20 hours, 1 minute ago -
Resolved : AutoCAD 2022 might not open after updating to 24H2
by
Alex5723
1 day, 14 hours ago -
Missing api-ms-win-core-libraryloader-11-2-1.dll
by
IreneLinda
13 hours, 3 minutes ago -
How Much Daylight have YOU Saved?
by
Nibbled To Death By Ducks
16 hours ago -
A brief history of Windows Settings
by
Simon Bisson
9 hours, 38 minutes ago -
Thunderbolt is not just for monitors
by
Ben Myers
8 hours, 15 minutes ago -
Password Generators — Your first line of defense
by
Deanna McElveen
13 hours, 42 minutes ago -
AskWoody at the computer museum
by
Will Fastie
9 hours, 17 minutes ago -
Planning for the unexpected
by
Susan Bradley
14 hours, 41 minutes ago -
Which printer type is the better one to buy?
by
Bob99
1 day, 15 hours ago -
Upgrading the web server
by
Susan Bradley
1 day, 14 hours ago -
New Windows 11 24H2 Setup – Initial Win Update prevention settings?
by
Tex265
2 days, 9 hours ago -
Creating a Google account
by
DavidofIN
2 days, 8 hours ago -
Undocumented “backdoor” found in Bluetooth chip used by a billion devices
by
Alex5723
2 days, 14 hours ago -
Microsoft Considering AI Models to Replace OpenAI’s in Copilot
by
Alex5723
3 days, 1 hour ago -
AI *emergent misalignment*
by
Alex5723
3 days, 2 hours ago -
Windows 11 Disk Encryption/ Bitlocker/ Recovery Key
by
Tex265
1 day, 10 hours ago -
Trouble signing out and restarting
by
Tech Hiker
10 hours, 5 minutes ago -
Windows 7 MSE Manual Updating
by
Microfix
6 hours, 53 minutes ago -
Problem running LMC 22 flash drive
by
Charlie
2 days, 10 hours ago -
Outlook Email Problem
by
Lil88reb
2 days, 10 hours ago -
“Microsoft 365 Office All-in-One For Dummies, 3rd Edition FREE
by
Alex5723
2 days, 17 hours ago -
Cant use Office 2013 – Getting error message about Office 2013
by
SAAR
3 days, 10 hours ago -
Nearly 1 million Windows devices targeted in advanced “malvertising” spree
by
bbearren
3 days, 10 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.