CVE-2021-27061 is a remote code execution vulnerability affecting Microsoft HEVC Video Extensions. With a CVSS score of 7.8 (High), it can be exploited locally with low attack complexity, potentially leading to high impact on confidentiality, integrity, and availability if a user is tricked into opening a malicious file. While not currently listed in CISA's KEV catalog, there is no public exploit code available in Metasploit or ExploitDB, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:high_efficiency_video_coding:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.