CVE-2016-0034
published 2016-01-13CVE-2016-0034: Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a…
PriorityP189high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2022-06-15
Exploited in the wild
EPSS
69.71%
99.3th percentile
Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka "Silverlight Runtime Remote Code Execution Vulnerability."
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | silverlight | >= 5.0 < 5.1.41212.0 | 5.1.41212.0 |
| msrc | microsoft_silverlight_5_developer_runtime_when_installed_on_apple_mac_os | — | — |
| msrc | microsoft_silverlight_5_developer_runtime_when_installed_on_microsoft_windows | — | — |
| msrc | microsoft_silverlight_5_when_installed_on_apple_mac_os | — | — |
| msrc | microsoft_silverlight_5_when_installed_on_microsoft_windows | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect delivery of malicious Silverlight .xap packages containing Shell_siver.dll and System.Xml.Linq.dll alongside AppManifest.xaml, as this combination was used to deliver the CVE-2016-0034 RCE exploit in the RATANKBA watering-hole campaign. ↗
- →CVE-2016-0034 exploits were integrated into Angler EK in February 2016; network traffic patterns consistent with Angler EK (fileless Bedep payload delivery, CryptXXX follow-on) should be correlated with Silverlight exploit attempts. ↗
- ·The exploit requires a crafted malicious decoder (user-overridable GetMaxByteCount and GetBytes functions) returning negative values; both GetMaxByteCount(1) and _encoder.GetBytes are attacker-controlled, enabling heap manipulation at an arbitrary negative offset. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck10.0CRITICAL
cisa8.8HIGH
vendor_msrc8.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Microsoft Silverlight Runtime Remote Code Execution Vulnerability
cisa·2022-05-25·CVSS 8.8
CVE-2016-0034 [HIGH] CWE-20 Microsoft Silverlight Runtime Remote Code Execution Vulnerability
Vulnerability: Microsoft Silverlight Runtime Remote Code Execution Vulnerability
Affected: Microsoft Silverlight
Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS).
Required Action: The impacted products are end-of-life and should be disconnected if still in use.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-0034
Remediation Due Date: 2022-06-15
Microsoft
CVE-2016-0034: Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:Yes
vendor_msrc·2016-01-12·CVSS 8.8
CVE-2016-0034 [HIGH] CVE-2016-0034: Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:Yes
VulDB
Microsoft Silverlight up to 5.1 Decoding input validation (MS16-006 / Nessus ID 87880)
vuldb·2026-04-23·CVSS 8.8
CVE-2016-0034 [HIGH] Microsoft Silverlight up to 5.1 Decoding input validation (MS16-006 / Nessus ID 87880)
A vulnerability identified as critical has been detected in Microsoft Silverlight up to 5.1. The affected element is an unknown function of the component Decoding Handler. Performing a manipulation results in improper input validation.
This vulnerability is cataloged as CVE-2016-0034. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
Applying a patch is the recommended action to fix this issue.
GHSA
GHSA-8wh9-64cq-2gj5: Microsoft Silverlight 5 before 5
ghsa_unreviewed·2022-05-14
CVE-2016-0034 [HIGH] CWE-20 GHSA-8wh9-64cq-2gj5: Microsoft Silverlight 5 before 5
Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka "Silverlight Runtime Remote Code Execution Vulnerability."
VulnCheck
Microsoft Silverlight Runtime Remote Code Execution Vulnerability
vulncheck·2016·CVSS 8.8
CVE-2016-0034 [HIGH] CWE-20 Microsoft Silverlight Runtime Remote Code Execution Vulnerability
Microsoft Silverlight Runtime Remote Code Execution Vulnerability
Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS).
Affected: Microsoft Silverlight
Required Action: The impacted products are end-of-life and should be disconnected if still in use.
Known Ransomware Campaign Use: Known
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2016-Jan; https://securelist.com/the-mysterious-case-of-cve-2016-0034-the-hunt-for-a-microsoft-silverlight-0-day/73255/; https://us-cert.cisa.gov/ncas/alerts/TA17-164A; https://cisa.gov/news-events/alerts/2017/06/13/hidden-cobra-north-koreas-ddos-botn
VulnCheck
Adobe Reader and Acrobat Sandbox Bypass Vulnerability
vulncheck·2014·CVSS 9.8
CVE-2014-0546 [CRITICAL] Adobe Reader and Acrobat Sandbox Bypass Vulnerability
Adobe Reader and Acrobat Sandbox Bypass Vulnerability
Adobe Reader and Acrobat on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context.
Affected: Adobe Acrobat and Reader
Required Action: Apply updates per vendor instructions.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://securelist.com/the-mysterious-case-of-cve-2016-0034-the-hunt-for-a-microsoft-silverlight-0-day/73255/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-06-15
VulnCheck
Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
vulncheck·2014·CVSS 10.0
CVE-2014-0515 [CRITICAL] Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in April 2014.
Affected: Adobe Flash Player
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.cve.org/CVERecord?id=CVE-2014-0515; https://unit42.paloaltonetworks.com/recent-watering-hole-attacks-attributed-apt-group-th3bug-using-poison-ivy/; https://www.fireeye.com/b
No detection rules found.
No public exploits indexed.
Securelist
YARA webinar follow up
blogs_securelist·2020-04-06·CVSS 8.8
[HIGH] YARA webinar follow up
Authors
- Costin Raiu
If you read my previous blogpost Hunting APTs with YARA then you probably know about the webinar we conducted on March 31, 2020, showcasing some of our experience in developing and using YARA rules for malware hunting.
In case you missed the webinar – or if you attended and want to re-watch it – you can find the recording here:
As requested by many of you, we are also making the slides available through SlideShare:
Unfortunately, we were forced to cut short the broadcast as we were running out of time. Nevertheless, we received a number of interesting questions and as I promised, I’ll try to answer them below. Thanks to everyone who participated and I appreciate all the feedback and ideas!
### YARA webinar – questions
1. Can you share the presentation? (multipl
Securelist
YARA webinar follow up
blogs_securelist·2020-04-06·CVSS 8.8
[HIGH] YARA webinar follow up
Authors
Costin Raiu
If you read my previous blogpost Hunting APTs with YARA then you probably know about the webinar we conducted on March 31, 2020, showcasing some of our experience in developing and using YARA rules for malware hunting.
In case you missed the webinar – or if you attended and want to re-watch it – you can find the recording here:
As requested by many of you, we are also making the slides available through SlideShare:
Unfortunately, we were forced to cut short the broadcast as we were running out of time. Nevertheless, we received a number of interesting questions and as I promised , I’ll try to answer them below. Thanks to everyone who participated and I appreciate all the feedback and ideas!
## YARA webinar – questions
Sure, please find the link above for SlideSha
Trendmicro
RATANKBA: Delving into Large-scale Watering Holes
blogs_trendmicro·2017-02-27
RATANKBA: Delving into Large-scale Watering Holes
Malware
## RATANKBA: Delving into Large-scale Watering Holes
We provide further analysis and insights regarding the RATANKBA malware, which was tied to malware attacks against banks in Poland, but also in a string of similar incidents involving financial institutions in different countries.
By: Trend Micro 2017/02/27 Read time: ( words)
Save to Folio
In early February, several financial organizations reported malware infection on their workstations, apparently coming from legitimate websites. The attacks turned out to be part of a large-scale campaign to compromise trusted websites in order to infect the systems of targeted enterprises across various industries. The strategy is typically known as a “ watering hole ” attack.
It was all sparked by a spate of recent malware attacks on P
Trendmicro
RATANKBA: Delving into Large-scale Watering Holes
blogs_trendmicro·2017-02-27
RATANKBA: Delving into Large-scale Watering Holes
Malware
# RATANKBA: Delving into Large-scale Watering Holes
We provide further analysis and insights regarding the RATANKBA malware, which was tied to malware attacks against banks in Poland, but also in a string of similar incidents involving financial institutions in different countries.
By: Trend Micro
2017/02/27
Read time: ( words)
Save to Folio
In early February, several financial organizations reported malware infection on their workstations, apparently coming from legitimate websites. The attacks turned out to be part of a large-scale campaign to compromise trusted websites in order to infect the systems of targeted enterprises across various industries. The strategy is typically known as a “watering hole” attack.
It was all sparked by a spate of recent malware attacks on Pol
Trendmicro
RATANKBA: Delving into Large-scale Watering Holes
blogs_trendmicro·2017-02-27
RATANKBA: Delving into Large-scale Watering Holes
Malware
## RATANKBA: Delving into Large-scale Watering Holes
We provide further analysis and insights regarding the RATANKBA malware, which was tied to malware attacks against banks in Poland, but also in a string of similar incidents involving financial institutions in different countries.
By: Trend Micro Feb 27, 2017 Read time: ( words)
Save to Folio
In early February, several financial organizations reported malware infection on their workstations, apparently coming from legitimate websites. The attacks turned out to be part of a large-scale campaign to compromise trusted websites in order to infect the systems of targeted enterprises across various industries. The strategy is typically known as a “ watering hole ” attack.
It was all sparked by a spate of recent malware attacks on
Unit42
Understanding Angler Exploit Kit - Part 2: Examining Angler EK
blogs_unit42·2016-06-07·CVSS 9.8
[CRITICAL] Understanding Angler Exploit Kit - Part 2: Examining Angler EK
This is the second part of a two-part blog post for understanding Angler exploit kit (EK). The first part covered EKs in general. This blog focuses on the Angler EK.
Angler is currently one of the most advanced, effective, and popular exploit kits in the cyber criminal market. It generally uses the most recent exploits based on the latest vulnerabilities. Like most leading EKs, the authors behind Angler use Software as a Service (SaaS) as their business model, and Angler can be rented in the cyber underground for a few thousand dollars a month.
### History
Angler EK was discovered in 2013, and it began appearing more frequently later that year. Angler grew in popularity sometime after Russian authorities arrested malware kingpin "Paunch", the alleged creator and distributor of Blackhole
Unit42
Understanding Angler Exploit Kit - Part 2: Examining Angler EK
blogs_unit42·2016-06-07
Understanding Angler Exploit Kit - Part 2: Examining Angler EK
Threat Research Center
Threat Research
Ransomware
## Understanding Angler Exploit Kit - Part 2: Examining Angler EK
Brad Duncan
Published: June 7, 2016
Malware
Ransomware
Threat Research
Angler Exploit Kit
CryptXXX
SaaS
This is the second part of a two-part blog post for understanding Angler exploit kit (EK). The first part covered EKs in general. This blog focuses on the Angler EK.
Angler is currently one of the most advanced, effective, and popular exploit kits in the cyber criminal market. It generally uses the most recent exploits based on the latest vulnerabilities. Like most leading EKs, the authors behind Angler use Software as a Service (SaaS) as their business model, and Angler can be rented in the cyber underground for a few thousand dollars a month .
## History
Qualys
Hunting For Vulnerable Functions In Microsoft Silverlight MS16-006 | Qualys
blogs_qualys·2016-01-15·CVSS 8.8
[HIGH] Hunting For Vulnerable Functions In Microsoft Silverlight MS16-006 | Qualys
This week Microsoft released a patch for a critical Silverlight issue, MS16-006, and since I worked on Silverlight signatures in the past it caught my eye. It’s a Remote Code Execution vulnerability which allows attackers to run code of his or her choice on the victim machine. I had a hunch that something more was hiding. I started to analyze it as soon as I finished writing signatures for the existing patch. When I was working on the analysis Kaspersky Lab published a great blog post about the story of this vulnerability.
In this blog, I’m presenting analysis of a different function that was also fixed in the same patch.
### Analysis of CVE-2016-0034 and the Patch
Silverlight is powered by the .NET Framework. Microsoft bulletin mentions "malicious decoder that can return negative offse
Qualys
Hunting For Vulnerable Functions In Microsoft Silverlight MS16-006 | Qualys
blogs_qualys·2016-01-14·CVSS 8.8
[HIGH] Hunting For Vulnerable Functions In Microsoft Silverlight MS16-006 | Qualys
This week Microsoft released a patch for a critical Silverlight issue, MS16-006, and since I worked on Silverlight signatures in the past it caught my eye. It’s a Remote Code Execution vulnerability which allows attackers to run code of his or her choice on the victim machine. I had a hunch that something more was hiding. I started to analyze it as soon as I finished writing signatures for the existing patch. When I was working on the analysis Kaspersky Lab published a great blog post about the story of this vulnerability.
In this blog, I’m presenting analysis of a different function that was also fixed in the same patch.
## Analysis of CVE-2016-0034 and the Patch
Silverlight is powered by the .NET Framework. Microsoft bulletin mentions "malicious decoder that can return negative offset
Talos
Microsoft Patch Tuesday - January 2016
blogs_talos·2016-01-12·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - January 2016
The first Patch Tuesday of 2016 has arrived. Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release is relatively light with nine bulletins addressing 25 vulnerabilities. Six bulletins are rated critical and address vulnerabilities in Edge, Internet Explorer, JScript/VBScript, Office, Silverlight, and Windows. The remaining three bulletins are rated important and address vulnerabilities in Exchange and several parts of Windows.
### Bulletins Rated Critical Microsoft bulletins MS16-001 through MS16-0006 are rated as critical in this month's release.
MS16-001 and MS16-002 are this month's Internet Explorer and Edge security bulletin respectively. In total, four vulnerabilities were addre
Talos
Microsoft Patch Tuesday - January 2016
blogs_talos·2016-01-12·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - January 2016
## Microsoft Patch Tuesday - January 2016
The first Patch Tuesday of 2016 has arrived. Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release is relatively light with nine bulletins addressing 25 vulnerabilities. Six bulletins are rated critical and address vulnerabilities in Edge, Internet Explorer, JScript/VBScript, Office, Silverlight, and Windows. The remaining three bulletins are rated important and address vulnerabilities in Exchange and several parts of Windows.
## Bulletins Rated Critical Microsoft bulletins MS16-001 through MS16-0006 are rated as critical in this month's release.
MS16-001 and MS16-002 are this month's Internet Explorer and Edge security bulletin respectively.
Bugzilla
CVE-2016-2339 ruby: Fiddle::Function.new heap buffer overflow
bugzilla·2017-01-12·CVSS 9.8
CVE-2016-2339 [CRITICAL] CVE-2016-2339 ruby: Fiddle::Function.new heap buffer overflow
CVE-2016-2339 ruby: Fiddle::Function.new heap buffer overflow
An exploitable heap overflow vulnerability exists in the Fiddle::Function.new “initialize” function functionality of Ruby. In Fiddle::Function.new “initialize” heap buffer “arg_types” allocation is made based on args array length. Specially constructed object passed as element of args array can increase this array size after mentioned allocation and cause heap overflow.
References:
http://www.talosintelligence.com/reports/TALOS-2016-0034/
Discussion:
Upstream patch:
https://github.com/ruby/ruby/commit/bcc2421b4938fc1d9f5f3fb6ef2320571b27af42
---
This flaw requires executing untrusted ruby code, or passing an untrusted class to the Fiddle module. Either of these would already represent a vulnerability by design, so the im
http://www.securitytracker.com/id/1034655https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-006http://www.securitytracker.com/id/1034655https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-006https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-0034
2016-01-13
Published
2022-05-25
Added to CISA KEV
Exploited in the wild