AV1 Video Extension Remote Code Execution Vulnerability
CVE-2023-29340
7.8HIGH
Summary
The AV1 Video Extension, developed by Microsoft, contains a vulnerability that could allow an attacker to execute arbitrary code on an affected system. This could lead to a range of malicious actions if exploited, as the attacker may gain control over the affected device. It is critical for users of the AV1 Video Extension to promptly apply the recommended updates from Microsoft to mitigate the risks associated with this vulnerability.
Affected Version(s)
AV1 Video Extension Unknown 1.1.0 < 1.1.60961.0
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved