CVE-2016-0034 is a critical remote code execution (RCE) and denial-of-service vulnerability affecting Microsoft Silverlight 5 before version 5.1.41212.0, stemming from improper handling of negative offsets during decoding. Rated 8.8 High on CVSS, this flaw allows unauthenticated attackers to achieve RCE with low complexity if a user visits a specially crafted website. It is actively exploited and listed in the KEV catalog, notably used in ransomware campaigns, and has a high EPSS score reflecting its real-world exploitability. While public exploit modules are not widely available, its presence in exploit kits and significant media coverage underscore the ongoing threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0, < 5.1.41212.0CPE matchmatch criteria | cpe:2.3:a:microsoft:silverlight:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.