cbcvebase.
CVE-2016-0034
published 2016-01-13

CVE-2016-0034: Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a…

PriorityP189high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2022-06-15
Exploited in the wild
EPSS
69.71%
99.3th percentile
Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka "Silverlight Runtime Remote Code Execution Vulnerability."

Affected

5 ranges
VendorProductVersion rangeFixed in
microsoftsilverlight>= 5.0 < 5.1.41212.05.1.41212.0
msrcmicrosoft_silverlight_5_developer_runtime_when_installed_on_apple_mac_os
msrcmicrosoft_silverlight_5_developer_runtime_when_installed_on_microsoft_windows
msrcmicrosoft_silverlight_5_when_installed_on_apple_mac_os
msrcmicrosoft_silverlight_5_when_installed_on_microsoft_windows

Detection & IOCsextracted from sources · hover to see the quote

domaineye-watch[.]in
filenamenbt_scan.exe
filenameShell_siver.dll
filenameAppManifest.xaml
  • Detect delivery of malicious Silverlight .xap packages containing Shell_siver.dll and System.Xml.Linq.dll alongside AppManifest.xaml, as this combination was used to deliver the CVE-2016-0034 RCE exploit in the RATANKBA watering-hole campaign.
  • CVE-2016-0034 exploits were integrated into Angler EK in February 2016; network traffic patterns consistent with Angler EK (fileless Bedep payload delivery, CryptXXX follow-on) should be correlated with Silverlight exploit attempts.
  • ·The exploit requires a crafted malicious decoder (user-overridable GetMaxByteCount and GetBytes functions) returning negative values; both GetMaxByteCount(1) and _encoder.GetBytes are attacker-controlled, enabling heap manipulation at an arbitrary negative offset.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck10.0CRITICAL
cisa8.8HIGH
vendor_msrc8.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.