CVE-2016-3367
published 2016-09-14CVE-2016-3367: StringBuilder in Microsoft Silverlight 5 before 5.1.50709.0 does not properly allocate memory for string-insert and string-append operations, which allows…
PriorityP357high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
17.79%
96.8th percentile
StringBuilder in Microsoft Silverlight 5 before 5.1.50709.0 does not properly allocate memory for string-insert and string-append operations, which allows remote attackers to execute arbitrary code via a crafted web site, aka "Microsoft Silverlight Memory Corruption Vulnerability."
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | silverlight | — | — |
| msrc | microsoft_silverlight_5_developer_runtime_when_installed_on_apple_mac_os | — | — |
| msrc | microsoft_silverlight_5_developer_runtime_when_installed_on_microsoft_windows | — | — |
| msrc | microsoft_silverlight_5_when_installed_on_apple_mac_os | — | — |
| msrc | microsoft_silverlight_5_when_installed_on_microsoft_windows | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-88qc-24w9-rxv7: StringBuilder in Microsoft Silverlight 5 before 5
ghsa_unreviewed·2022-05-14
CVE-2016-3367 [HIGH] CWE-119 GHSA-88qc-24w9-rxv7: StringBuilder in Microsoft Silverlight 5 before 5
StringBuilder in Microsoft Silverlight 5 before 5.1.50709.0 does not properly allocate memory for string-insert and string-append operations, which allows remote attackers to execute arbitrary code via a crafted web site, aka "Microsoft Silverlight Memory Corruption Vulnerability."
Microsoft
Microsoft Silverlight Memory Corruption Vulnerability
vendor_msrc·2016-09-13·CVSS 8.8
CVE-2016-3367 [HIGH] Microsoft Silverlight Memory Corruption Vulnerability
Microsoft Silverlight Memory Corruption Vulnerability
Description: A remote code execution vulnerability exists when Microsoft Silverlight improperly allows applications to access objects in memory. The vulnerability could corrupt system memory, which could allow an attacker to execute arbitrary code. In a web-browsing scenario, an attacker who successfully exploited this vulnerability could obtain the same permissions as the currently logged-on user. If a user is logged on with administrative user rights, an attacker could take complete control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than us
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/92837http://www.securitytracker.com/id/1036795https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-109http://www.securityfocus.com/bid/92837http://www.securitytracker.com/id/1036795https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-109
2016-09-14
Published