Vulnerability record · CVE-2016-0034 · published 13 January 2016
CVE-2016-0034: Microsoft Silverlight negative offset decoding flaw allows remote code execution
Microsoft · Silverlight
Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, corrupting object headers. A remote attacker can exploit this through a crafted website to run arbitrary code or cause a denial of service. The flaw is serious because it is remotely reachable and has been exploited in the wild.
Description
Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka "Silverlight Runtime Remote Code Execution Vulnerability."
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw allows unauthenticated remote code execution, is listed in CISA KEV with known ransomware use, and has a very high EPSS score, though it requires user interaction.
What it is
Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, corrupting object headers. A remote attacker can exploit this through a crafted website to run arbitrary code or cause a denial of service. The flaw is serious because it is remotely reachable and has been exploited in the wild.
Impact
An attacker gains arbitrary code execution in the context of the Silverlight runtime, or can crash it to cause a denial of service. Successful exploitation could lead to full compromise of the affected host.
Attack surface
Reached over the network via a crafted website that triggers the decoding flaw, requiring user interaction (the victim must visit the page or load the content). No authentication or privileges are needed on the target.
Exploitation
Listed in CISA KEV with a 2022-05-25 addition and known ransomware campaign use, and EPSS probability of 0.696 (99.3rd percentile), indicating active exploitation. A vendor patch (MS16-006) is referenced.
What to do
- Apply Microsoft security bulletin MS16-006 to update Silverlight to 5.1.41212.0 or later.
- Since Silverlight is end-of-life, disconnect or remove it from systems where it is no longer required, per CISA guidance.
- Disable or uninstall the Silverlight browser plug-in and block its content from untrusted sites.
- Restrict browsing to trusted sites and enforce network controls to reduce exposure to crafted pages.
- Monitor for and isolate any remaining end-of-life Silverlight installations.
Detection
- Hunt for Silverlight processes (e.g., plugin-container or iexplore loading npctrl.dll) spawning unexpected child processes.
- Monitor for crashes or object-header corruption events in Silverlight runtime logs.
- Detect network requests to sites serving Silverlight (.xap) content from untrusted or newly seen domains.
- Review endpoint telemetry for code execution originating from browser plug-in processes on hosts with Silverlight installed.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2016-0034 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Microsoft Silverlight Runtime Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: The impacted products are end-of-life and should be disconnected if still in use. Federal deadline 15 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securitytracker.com/id/1034655 | Broken LinkThird Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-006 | PatchVendor Advisory |
| http://www.securitytracker.com/id/1034655 | Broken LinkThird Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-006 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-0034 | US Government Resource |
Track CVE-2016-0034 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-0034), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.