CVE-2022-22709 is a remote code execution vulnerability affecting Microsoft VP9 Video Extensions. With a CVSS score of 7.8 (High), successful exploitation requires user interaction (UI:R) and could lead to high confidentiality, integrity, and availability impacts (C:H/I:H/A:H) if an attacker can trick a user into opening a specially crafted file. While not currently listed on CISA's KEV catalog or having public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community. Organizations should prioritize patching to mitigate the risk associated with this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.42791.0CPE matchmatch criteria | cpe:2.3:a:microsoft:vp9_video_extensions:*:*:*:*:*:*:*:* | ||
>= 1.0.0.0, < 1.0.42791.0CPE match | cpe:2.3:a:microsoft:vp9_video_extensions:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.