CVE-2016-0034

CVE Published 2016-01-13
Related CWE(s) CWE-20: Improper Input Validation
Related Vendor(s) microsoft
Related Product(s) silverlight
Exploitation Reported (CISA KEV) 2022-05-25
CVSS 3 Base Score 8.8 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka "Silverlight Runtime Remote Code Execution Vulnerability."

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References