CVE-2022-22018
CVSS 2.0 Score 6.8 of 10 (medium)
Details
Summary
CVE-2022-22018 is a remote code execution vulnerability affecting HEVC Video Extensions. Maliciously crafted HEVC video files can be used to exploit this weakness, allowing attackers to execute arbitrary code on vulnerable systems. Successful exploitation could lead to significant security risks, including data theft, unauthorized system access, and the installation of malware. This vulnerability highlights the importance of keeping software up-to-date with the latest security patches. Users and organizations are strongly advised to apply the available fixes as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft HEVC Video Extensions
Affected Vendors
- Microsoft