Government warns of remote attack against Windows PCs editing iPhone video

If you own a Windows PC as well as a recent iPhone, the U.S. government wants you to open the Windows Store today and make sure that you have the most recent version of the HEVC video codec.

The U.S. government (specifically the Cybersecurity and Infrastructure Security Agency) has warned that the Microsoft Windows Codecs Library includes a vulnerability that affects how it handles objects stored in memory. Specifically, a specially-crafted image file could be used to remotely take over your machine unless your PC is patched.

Many attacks against PCs require local access, or the actual presence of a bad guy sitting at your keyboard. What the U.S. CISA is worried about is the presence of an HEVC file specifically designed to take over your PC. And it’s no idle threat; our colleagues at Macworld report that recording video using HEVC occurs by default on iOS 11 and later, meaning that you most likely won’t be suspicious of an HEVC video attached to an email or on the Internet.

If you don’t own an iPhone, chances are that you’re not vulnerable. You’ll need to have downloaded the optional HEVC or “HEVC from Device Manufacturer” media codecs from the Microsoft Store to be vulnerable.

To patch the problem, you’ll need to download the updated codec from the Store, too. The patched versions of the codec include versions 1.0.32762.0, 1.0.32763.0, and later. To check to see if you have the updated version, go to the Windows 10 Settings menu, then to Apps & Features and then to HEVC, and Advanced Options. You’ll see the version number there. You can also launch PowerShell from within Windows and type in the following command to see the version number, too:

U.S. CISA also warns that a second, unrelated vulnerability applies to Visual Studio, and a malformed JSON file. Although Visual Studio usually only applies to developers, if you’re a user of that program, you’ll need to be wary of JSON files until Microsoft develops a patch.

Gregory E. Crayton
Gregory E. Crayton has around 5+ years of experience in market research and consulting services for ICT & Semiconductor domain. He holds varied experience in market sizing and forecasting with varied models, competition landscape, consumer behavior analysis, opportunity analysis, product/company benchmarking, data mining, and others.

Related Articles

Bollyshare 2020: HD Bollywood and Hollywood Movies Download

As it seems, the web has appeared as one of the biggest blessings for the movie watchers. There are many platforms where movies are...

3movierulz 2020: HD Bollywood Movies, Hollywood Full Movies Download

Have you ever wondered why online movie streaming services are gaining never-ending popularity in recent times? It's because people get access to an unlimited...

Microsoft begins rolling out Windows 10 version 20H2

Windows 10 users running version 1903 or later can now update to Microsoft’s latest publicly available build - Windows 10 version 20H2. The October...

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Stay Connected

0FansLike
2,456FollowersFollow
0SubscribersSubscribe
- Advertisement -

Latest Articles

Bollyshare 2020: HD Bollywood and Hollywood Movies Download

As it seems, the web has appeared as one of the biggest blessings for the movie watchers. There are many platforms where movies are...

3movierulz 2020: HD Bollywood Movies, Hollywood Full Movies Download

Have you ever wondered why online movie streaming services are gaining never-ending popularity in recent times? It's because people get access to an unlimited...

Microsoft begins rolling out Windows 10 version 20H2

Windows 10 users running version 1903 or later can now update to Microsoft’s latest publicly available build - Windows 10 version 20H2. The October...

Gone But Not Forgotten: Compaq

While computers had finally made the big jump from machines that took up the better portion of a room to something that could fit...

Apple releases iOS 14.1 with support for iPhone 12, 10-bit HDR, and bug fixes

Apple has release iOS 14.1, a sort of intermediary release between the big iOS 14 release a month ago, and the iOS 14.2...