Microsoft Windows Raw Image Extensions Library RCE (December 2022)

high Nessus Plugin ID 168684

Version 1.6

Mar 27, 2024, 7:16 PM

  • Detection (store app vuln plugins will require paranoia when we are unable to determine path)

Plugin Feed: 202403271916

Version 1.5

Jan 12, 2023, 11:00 PM

  • IAVM reference

Plugin Feed: 202301122300

Version 1.4

Dec 16, 2022, 6:16 PM

  • IAVM reference
  • STIG Severity (set to "I")

Plugin Feed: 202212161816

Version 1.3

Dec 14, 2022, 1:51 PM

  • CVSS metrics ("CVSSv2 vector" changed from "CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C" to "CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C")
  • CVSS metrics ("CVSSv2 score" changed from "6.8" to "7.2")
  • CVSS metrics ("CVSSv3 score" changed from "7.3" to "7.8")
  • CVSS metrics ("CVSSv3 vector" changed from "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" to "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H")
  • CVSS temporal metrics ("CVSSv2 temporal vector" set to "CVSS2#E:U/RL:OF/RC:C")
  • CVSS temporal metrics ("CVSSv3 temporal vector" set to "CVSS:3.0/E:U/RL:O/RC:C")
  • CVSSv2 severity (based on CVE-2022-44687, severity increased from "Medium" to "High")
  • CVSSv3 score source (set to "CVE-2022-44687")
  • Exploit attributes ("Exploit available" set to "False")

Plugin Feed: 202212141351

Version 1.2

Dec 14, 2022, 5:50 AM

  • New

Plugin Feed: 202212140550

* Changelogs are generally available for changes made after Nov 1, 2022