EXPOSURES › CVE-2016-0034
CVE-2016-0034
CRITICAL ⌖ ON CISA KEV · EXPLOITEDMicrosoft Silverlight's remote code execution vulnerability was actively exploited in the wild and linked to ransomware attacks.
The Silverlight runtime mishandled negative offsets during decoding, allowing attackers to execute arbitrary code remotely. This unpatched vulnerability was actively exploited in the wild and linked to ransomware, demonstrating the severe impact of neglecting known CVEs in legacy software. DIB organizations must ensure all legacy components are patched or decommissioned to prevent similar exposures.
Shame score — A known, actively exploited vulnerability in a legacy runtime was left unpatched and directly linked to ransomware attacks, showing severe negligence in maintaining software hygiene.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS).
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |