Executive brief
Microsoft Silverlight mishandles negative offsets during decoding, leading to object-header corruption. This vulnerability allows remote attackers to execute arbitrary code or cause a denial of service via a crafted website.
Affected products
- Microsoft Silverlight 5 before 5.1.41212.0
Timeline
- 2016-01-13: disclosed: Initial NVD publication date
- 2016-01-13: advisory: Microsoft security bulletin MS16-006 released
- 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-05-25: exploited: Confirmed exploited in the wild per CISA KEV entry