CVE-2022-24451 is a remote code execution vulnerability affecting Microsoft VP9 Video Extensions. With a CVSS score of 7.8 (HIGH), this vulnerability requires user interaction (UI:R) and local access (AV:L) for an attacker to achieve high impact on confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog and lacking public exploit code in Metasploit or ExploitDB, it has received limited community discussion and media coverage, primarily noted in Microsoft's March 2022 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.42791.0CPE matchmatch criteria | cpe:2.3:a:microsoft:vp9_video_extensions:*:*:*:*:*:*:*:* | ||
>= 1.0.0.0, < 1.0.42791.0CPE match | cpe:2.3:a:microsoft:vp9_video_extensions:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.