CVE-2016-0185 is a critical remote code execution vulnerability affecting Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 through crafted Media Center link (.mcl) files. With a CVSS score of 7.8 (High), it allows unauthenticated attackers to execute arbitrary code on a vulnerable system if a user opens a malicious .mcl file. This vulnerability is actively exploited in the wild, as confirmed by its presence in CISA's KEV catalog, and public exploit code is available, indicating a high risk of compromise. The vulnerability has garnered significant community attention, despite limited media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.