Vulnerability record · CVE-2016-0185 · published 11 May 2016
CVE-2016-0185: Microsoft Windows Media Center .mcl File Remote Code Execution
Microsoft · Windows 7
Windows Media Center on Vista SP2, Windows 7 SP1, and Windows 8.1 fails to properly handle a crafted Media Center link (.mcl) file, allowing arbitrary code execution. Because the flaw is reachable through a file a victim opens, it remains a practical risk on any unpatched legacy Windows endpoint where Media Center is present.
Description
Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted Media Center link (aka .mcl) file, aka "Windows Media Center Remote Code Execution Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with a very high EPSS score and public exploit code, but requires user interaction and affects only legacy, largely unsupported Windows versions.
What it is
Windows Media Center on Vista SP2, Windows 7 SP1, and Windows 8.1 fails to properly handle a crafted Media Center link (.mcl) file, allowing arbitrary code execution. Because the flaw is reachable through a file a victim opens, it remains a practical risk on any unpatched legacy Windows endpoint where Media Center is present.
Impact
An attacker who gets a victim to open a malicious .mcl file can execute arbitrary code in the context of the logged-on user, giving full control of confidentiality, integrity, and availability on that host.
Attack surface
Reached locally by opening a crafted .mcl file; the CVSS vector shows no privileges required but user interaction required, so the victim must open the file or link. No network service exposure is described.
Exploitation
It is listed in CISA KEV (added 2021-11-03), and EPSS is very high at roughly 0.70 (99th percentile), with a public Exploit-DB entry referenced, indicating known exploitation activity.
What to do
- Apply the Microsoft MS16-059 security update on all affected Windows Vista SP2, Windows 7 SP1, and Windows 8.1 systems.
- Remove or disable Windows Media Center where it is not required, since these platforms are out of support.
- Block or quarantine .mcl file attachments and downloads at email and web gateways.
- Restrict user ability to open untrusted file types via application control or file association hardening.
- Prioritize migration off end-of-life Windows versions that cannot receive current patches.
Detection
- Monitor process creation for wmc.exe or Media Center processes spawned from user download or temp directories.
- Alert on .mcl file creation or execution events in endpoint telemetry.
- Hunt for suspicious child processes (script interpreters, cmd, powershell) launched by Media Center binaries.
- Review email and web proxy logs for .mcl attachments or downloads reaching affected hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2016-0185 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Windows Media Center Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/90023 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1035832 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.zerodayinitiative.com/advisories/ZDI-16-277 | Third Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-059 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/39805/ | Third Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/90023 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1035832 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.zerodayinitiative.com/advisories/ZDI-16-277 | Third Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-059 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/39805/ | Third Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-0185 | US Government Resource |
Track CVE-2016-0185 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-0185), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.