CVE-2016-0034
Microsoft Silverlight Runtime Remote Code Execution Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka "Silverlight Runtime Remote Code Execution Vulnerability."
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 69.61% probability · 99th percentile
- CISA KEV
- Listed 25 May 2022 · due 15 June 2022 · used in ransomware campaigns
- Affected
- microsoft/silverlight
- Source
- secure@microsoft.com
CISA notes
The impacted products are end-of-life and should be disconnected if still in use. https://nvd.nist.gov/vuln/detail/CVE-2016-0034
References
- http://www.securitytracker.com/id/1034655Broken Link, Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-006Patch, Vendor Advisory
- http://www.securitytracker.com/id/1034655Broken Link, Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-006Patch, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-0034US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.