← Vulnerability feed

Vulnerability record · CVE-2016-0034 · published 13 January 2016

CVE-2016-0034: Microsoft Silverlight negative offset decoding flaw allows remote code execution

Microsoft · Silverlight

Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, corrupting object headers. A remote attacker can exploit this through a crafted website to run arbitrary code or cause a denial of service. The flaw is serious because it is remotely reachable and has been exploited in the wild.

8.8 CVSS 3.1 High CISA KEV since 25 May 2022 Known ransomware use EPSS 69% · top 0.7%
8.8CVSS 3.1 base score, v2 9.3
69%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
14 Aug 2026Last modified by NVD

Description

Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka "Silverlight Runtime Remote Code Execution Vulnerability."

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw allows unauthenticated remote code execution, is listed in CISA KEV with known ransomware use, and has a very high EPSS score, though it requires user interaction.

What it is

Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, corrupting object headers. A remote attacker can exploit this through a crafted website to run arbitrary code or cause a denial of service. The flaw is serious because it is remotely reachable and has been exploited in the wild.

Impact

An attacker gains arbitrary code execution in the context of the Silverlight runtime, or can crash it to cause a denial of service. Successful exploitation could lead to full compromise of the affected host.

Attack surface

Reached over the network via a crafted website that triggers the decoding flaw, requiring user interaction (the victim must visit the page or load the content). No authentication or privileges are needed on the target.

Exploitation

Listed in CISA KEV with a 2022-05-25 addition and known ransomware campaign use, and EPSS probability of 0.696 (99.3rd percentile), indicating active exploitation. A vendor patch (MS16-006) is referenced.

What to do

  • Apply Microsoft security bulletin MS16-006 to update Silverlight to 5.1.41212.0 or later.
  • Since Silverlight is end-of-life, disconnect or remove it from systems where it is no longer required, per CISA guidance.
  • Disable or uninstall the Silverlight browser plug-in and block its content from untrusted sites.
  • Restrict browsing to trusted sites and enforce network controls to reduce exposure to crafted pages.
  • Monitor for and isolate any remaining end-of-life Silverlight installations.

Detection

  • Hunt for Silverlight processes (e.g., plugin-container or iexplore loading npctrl.dll) spawning unexpected child processes.
  • Monitor for crashes or object-header corruption events in Silverlight runtime logs.
  • Detect network requests to sites serving Silverlight (.xap) content from untrusted or newly seen domains.
  • Review endpoint telemetry for code execution originating from browser plug-in processes on hosts with Silverlight installed.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2016-0034 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Microsoft Silverlight Runtime Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: The impacted products are end-of-life and should be disconnected if still in use. Federal deadline 15 June 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-0034 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2015-1671Microsoft DirectWrite TrueType Font Parsing Remote Code ExecutionThe Windows DirectWrite library fails to properly handle crafted TrueType fonts, allowing memory corruption that can lead to arbitrary code execution…KEVEPSS 49%analysed7.8CVE-2013-0074Microsoft Silverlight pointer validation flaw enables remote code executionMicrosoft Silverlight 5 and the 5 Developer Runtime before 5.1.20125.0 fail to properly validate pointers during HTML object rendering. A crafted Sil…KEVEPSS 79%analysed5.5CVE-2013-3896Microsoft Silverlight pointer validation flaw leaks sensitive informationMicrosoft Silverlight 5 before 5.1.20913.0 fails to properly validate pointers during access to Silverlight elements, allowing a crafted Silverlight …KEVEPSS 68%analysed9.3CVE-2015-6166Microsoft silverlight memory buffer overflow vulnerabilityMicrosoft Silverlight 5 before 5.1.41105.00 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read or wri…EPSS 14%9.3CVE-2015-6108Microsoft live meeting memory buffer overflow vulnerabilityThe Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8; Windows 8.1; Windows Server 20…EPSS 26%9.3CVE-2015-2464Microsoft .net framework improper input validation vulnerabilityMicrosoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT G…EPSS 36%9.3CVE-2015-2463Microsoft .net framework improper input validation vulnerabilityMicrosoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT G…EPSS 34%9.3CVE-2015-2456Microsoft .net framework improper input validation vulnerabilityMicrosoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT G…EPSS 36%

Source: NIST National Vulnerability Database (record CVE-2016-0034), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.