EXPOSURES › CVE-2016-0185
CVE-2016-0185
HIGH ⌖ ON CISA KEV · EXPLOITEDA remote code execution flaw in Windows Media Center allowed attackers to execute arbitrary code via malicious .mcl files.
An unpatched remote code execution vulnerability in Windows Media Center enabled attackers to execute arbitrary code when opening specially crafted .mcl files. This failure is critical for DIB organizations because it represents a known, unpatched CVE that was actively exploited in the wild, directly violating the requirement to patch known vulnerabilities and exposing systems to remote compromise. Organizations must ensure all legacy and specialized software like Media Center is patched or removed to prevent similar exploits.
Shame score — Microsoft failed to patch a known, actively exploited remote code execution vulnerability in a consumer-facing product, demonstrating negligence in maintaining a secure software supply chain.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Media Center contains a remote code execution vulnerability when Windows Media Center opens a specially crafted Media Center link (.mcl) file that references malicious code.
"Microsoft Windows Media Center contains a remote code execution vulnerability when Windows Media Center opens a specially crafted Media Center link (.mcl) file that references malicious code."
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |