CVE-2016-0147
published 2016-04-12CVE-2016-0147: Microsoft XML Core Services 3.0 allows remote attackers to execute arbitrary code via a crafted web site, aka "MSXML 3.0 Remote Code Execution Vulnerability."
PriorityP277high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
15.71%
96.5th percentile
Microsoft XML Core Services 3.0 allows remote attackers to execute arbitrary code via a crafted web site, aka "MSXML 3.0 Remote Code Execution Vulnerability."
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | xml_core_services | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2016-0147 is exploited via a malicious website serving crafted XML content to the target; monitor for suspicious msxml.dll activity triggered by browser or web-facing processes. ↗
- →CVE-2016-0147 was suspected to have been used by the ScarCruft APT group; detections for ScarCruft payloads should be correlated with MSXML 3.0 exploitation activity. ↗
- →ScarCruft (Operation Daybreak) used spear-phishing emails pointing to a hacked website hosting the exploit, which performed browser checks before redirecting to an attacker-controlled server in Poland. ↗
- →The exploitation chain involved three Flash objects; the vulnerability-triggering object was located in the second SWF file delivered to the victim. ↗
- ·CVE-2016-0147 specifically affects Microsoft XML Core Services 3.0 (MSXML 3.0); the patched component is msxml.dll, updated via bulletin MS16-040. ↗
- ·Attribution of CVE-2016-0147 zero-day use to ScarCruft is assessed with uncertainty ('we think'); treat as suspected rather than confirmed. ↗
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7r55-xf64-gwj6: Microsoft XML Core Services 3
ghsa_unreviewed·2022-05-14
CVE-2016-0147 [HIGH] CWE-20 GHSA-7r55-xf64-gwj6: Microsoft XML Core Services 3
Microsoft XML Core Services 3.0 allows remote attackers to execute arbitrary code via a crafted web site, aka "MSXML 3.0 Remote Code Execution Vulnerability."
VulnCheck
Microsoft XMP Core Services Improper Input Validation
vulncheck·2016·CVSS 8.8
CVE-2016-0147 [HIGH] Microsoft XMP Core Services Improper Input Validation
Microsoft XMP Core Services Improper Input Validation
Microsoft XML Core Services 3.0 allows remote attackers to execute arbitrary code via a crafted web site, aka "MSXML 3.0 Remote Code Execution Vulnerability."
Affected: Microsoft XMP Core Services
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://securelist.com/cve-2016-4171-adobe-flash-zero-day-used-in-targeted-attacks/75082/; https://securelist.com/operation-daybreak/75100/
No detection rules found.
No public exploits indexed.
Securelist
IT threat evolution in Q2 2016. Overview
blogs_securelist·2016-08-11
IT threat evolution in Q2 2016. Overview
Table of Contents
- Targeted attacks and malware campaigns
- Malware stories
- Data breaches
Authors
- David Emm
- Roman Unuchek
Download the full report (PDF)
## Targeted attacks and malware campaigns
### Cha-ching! Skimming off the cream
Earlier in the year, as part of an incident response investigation, we uncovered a new version of the Skimer ATM malware. The malware, which first surfaced in 2009, has been re-designed. So too have the tactics of the cybercriminals using it. The new ATM infector has been targeting ATMs around the world, including the UAE, France, the United States, Russia, Macau, China, the Philippines, Spain, Germany, Georgia, Poland, Brazil and the Czech Republic.
Rather than the well-established method of fitting a fake card-reader to the ATM, the attackers
Qualys
Patch Tuesday April 2016 | Qualys
blogs_qualys·2016-04-12·CVSS 7.8
[HIGH] Patch Tuesday April 2016 | Qualys
It is time for Patch Tuesday April 2016, and we have some insight into what is coming at us already. Last week Adobe had to anticipate their monthly Adobe Flash Player ( APSB16-10 ) patch to help their users defend against a 0-day that was being exploited in the wild and a couple of weeks ago we heard of the “Badlock” vulnerability from the Samba development team – both Windows and Samba on Linux/Unix are affected.
But Badlock seems to be tamer than expected – it is addressed by Microsoft in MS16-047 , a bulletin categorized as “important”. It is a Man-in-the-Middle type vulnerability and can be used to login as another user for applications that use the SAMR or LSAD protocol – the SMB protocol is not affected. All versions of Windows are affected – Vista to Server 2012R2. We are not sure
Qualys
Patch Tuesday April 2016 | Qualys
blogs_qualys·2016-04-12·CVSS 7.8
[HIGH] Patch Tuesday April 2016 | Qualys
It is time for Patch Tuesday April 2016, and we have some insight into what is coming at us already. Last week Adobe had to anticipate their monthly Adobe Flash Player (APSB16-10) patch to help their users defend against a 0-day that was being exploited in the wild and a couple of weeks ago we heard of the “Badlock” vulnerability from the Samba development team – both Windows and Samba on Linux/Unix are affected.
But Badlock seems to be tamer than expected – it is addressed by Microsoft in MS16-047, a bulletin categorized as “important”. It is a Man-in-the-Middle type vulnerability and can be used to login as another user for applications that use the SAMR or LSAD protocol – the SMB protocol is not affected. All versions of Windows are affected – Vista to Server 2012R2. We are not sure wh
Zscaler
Zscaler found Multiple Security Vulnerabilities | 04-12-2016
blogs_zscaler·CVSS 7.5
[HIGH] Zscaler found Multiple Security Vulnerabilities | 04-12-2016
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
arXiv
Hesperus is Phosphorus: Mapping Threat Actor Naming Taxonomies at Scale
arxiv_fulltext·2025-11-30
Hesperus is Phosphorus: Mapping Threat Actor Naming Taxonomies at Scale
1
.001
Hesperus is Phosphorus
Roa, Suarez, and Tapiador
[mode = title]Hesperus is Phosphorus: Mapping Threat Actor Naming Taxonomies at Scale
[1]
[1]
This research was supported by MICIU/AEI/10.13039/501100011033 under Grant
No. PID2022-140126OB-I00 (CYCAD) and INCIBE under Grant APAMCiber. The opinions, findings, and conclusions or recommendations expressed are those of the authors and do not necessarily reflect those of any of the funding agencies.
Gonzalo Roa
[email protected]
Data curation, Methodology, Software, Analysis, Writing, Visualization
Manuel Suarez-Roman[orcid=0009-0008-2569-6178]
[email protected]
Data curation, Methodology, Software, Analysis, Writing, Visualization
Juan Tapiador[orcid=0000-0002-4573-3967]
[email protected]
Conceptualization, Methodolo
2016-04-12
Published
Exploited in the wild