Executive brief
Microsoft Windows Media Center contains a remote code execution vulnerability when processing specially crafted Media Center link (.mcl) files. An attacker can execute arbitrary code if a user opens a malicious .mcl file that references malicious code.
Affected products
- Microsoft Windows Vista SP2
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1
Timeline
- 2016-05-10: disclosed: Initial disclosure and Microsoft security bulletin MS16-059 published.
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2021-11-03: exploited: Confirmed as exploited in the wild.