⚠ Actively exploited in ransomware campaigns
This vulnerability is on the CISA Known Exploited Vulnerabilities list and has been used in known ransomware attacks. CISA required action: The impacted products are end-of-life and should be disconnected if still in use.. Due date: 2022-06-15.

CVE-2016-0034

Severity
8.8HIGH
EPSS
52.8%
top 2.05%
CISA KEV
KEVRansomware
Added 2022-05-25
Due 2022-06-15
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedJan 13
KEV addedMay 25
KEV dueJun 15
CISA Required Action: The impacted products are end-of-life and should be disconnected if still in use.

Description

Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka "Silverlight Runtime Remote Code Execution Vulnerability."

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

NVDmicrosoft/silverlight5.05.1.41212.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-8wh9-64cq-2gj5: Microsoft Silverlight 5 before 52022-05-14
CVEList
CVE-2016-0034: Microsoft Silverlight 5 before 52016-01-13
VulnCheck
Microsoft Silverlight Runtime Remote Code Execution Vulnerability2016

📋Vendor Advisories

2
CISA
Microsoft Silverlight Runtime Remote Code Execution Vulnerability2022-05-25
Microsoft
CVE-2016-0034: Impact: Remote Code Execution Exploit Status: Publicly Disclosed:No;Exploited:Yes2016-01-12

🕵️Threat Intelligence

1
Qualys
Hunting For Vulnerable Functions In Microsoft Silverlight MS16-006 | Qualys2016-01-14

💬Community

1
Bugzilla
CVE-2016-2339 ruby: Fiddle::Function.new heap buffer overflow2017-01-12
CVE-2016-0034 (HIGH CVSS 8.8) | Microsoft Silverlight 5 before 5.1. | cvebase.io