Junglewise Threat Intelligence

CVE-2016-0034: Microsoft Silverlight Runtime Remote Code Execution Vulnerability

CVE-2016-0034 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-05-25

Technologies: Microsoft Silverlight. Vendors: Microsoft.

Executive brief

Microsoft Silverlight mishandles negative offsets during decoding, leading to object-header corruption. This vulnerability allows remote attackers to execute arbitrary code or cause a denial of service via a crafted website.

Affected products

  • Microsoft Silverlight 5 before 5.1.41212.0

Timeline

  • 2016-01-13: disclosed: Initial NVD publication date
  • 2016-01-13: advisory: Microsoft security bulletin MS16-006 released
  • 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-05-25: exploited: Confirmed exploited in the wild per CISA KEV entry

Related threats