CVE Tools

Description

Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka "Silverlight Runtime Remote Code Execution Vulnerability."

In plain language

AI Act now

CVE-2016-0034 is a Silverlight 5 problem where visiting a malicious website can crash your computer or let an attacker run code—if you still use Silverlight 5, you should act now.

Executive summary

CVE-2016-0034 is a remote attack against Microsoft Silverlight via crafted web content that abuses negative offset handling during decoding, enabling remote code execution or denial of service; exploitation is confirmed by CISA KEV and Silverlight is end-of-life.

If affected, business impact
Full application compromiseWidespread malware/ransomware riskService disruption and downtimePossible data theft risk

What to do now

  1. Check whether any of your computers use Microsoft Silverlight 5 (especially if staff browse internal or external sites that may load Silverlight content).
  2. Verify installed Silverlight 5 version; consider the system impacted if it is older than 5.1.41212.0.
  3. Remove or disable Silverlight on business workstations that don’t require it, and block Silverlight content in browsers when possible.
  4. If Silverlight must remain for a specific application, upgrade to Silverlight 5 fixed version 5.1.41212.0 (per MS16-006 guidance) and then retest that the required sites/features still work.
  5. Disconnect any system that still has impacted Silverlight in place but cannot be updated or disabled, and prioritize replacing the end-of-life dependency with a modern alternative.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:NAC:LPR:NUI:RS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:RUser Interaction
Required
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

Microsoft Corp
commercial·USaka microsoft, microsoft corporation
and 2 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:May 25, 2022
Remediation due:Jun 15, 2022
Ransomware:Known ransomware use

Required action: The impacted products are end-of-life and should be disconnected if still in use.

Official Patch Available

References

and 1 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2016-0034 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows