CVE-2016-0034: Microsoft Silverlight Runtime Remote Code Execution Vulnerability
Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka "Silverlight Runtime Remote Code Execution Vulnerability."
Other sources
Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS).
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Microsoft Silverlightto a version that resolves this vulnerability.Fixed in 5.1.41212.0 - Compensating control
Disconnect Microsoft Silverlight instances from the network if they are still in use, since the impacted products are end-of-life.
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0034?
CVE-2016-0034 has a severity rating of critical due to the potential for remote code execution.
How do I fix CVE-2016-0034?
To mitigate CVE-2016-0034, users should upgrade to Microsoft Silverlight version 5.1.41212.0 or later.
Who is affected by CVE-2016-0034?
CVE-2016-0034 affects all versions of Microsoft Silverlight prior to 5.1.41212.0.
What type of attack can exploit CVE-2016-0034?
CVE-2016-0034 can be exploited through crafted websites that trigger remote code execution or denial of service.
Is there a workaround for CVE-2016-0034?
The best workaround for CVE-2016-0034 is to uninstall Microsoft Silverlight until a patch is applied.