CVE-2016-0185

HIGH KEV

Microsoft Windows Media Center - Remote Code Execution via Crafted MCL File

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2016-0185 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021. EIP tracks 1 public exploit from researchers including Eduardo Braun Prado.

AI-analyzed exploit summary This exploit leverages a vulnerability in Microsoft Windows Media Center where specially crafted .MCL files can bypass security warnings to execute arbitrary code via remote shares. The PoC demonstrates RCE by using a Control Panel Shortcut to execute a CPL file from a remote location.

Description

Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted Media Center link (aka .mcl) file, aka "Windows Media Center Remote Code Execution Vulnerability."

Exploits (1)

exploitdb WORKING POC VERIFIED
by Eduardo Braun Prado · textremotewindows
https://www.exploit-db.com/exploits/39805

This exploit leverages a vulnerability in Microsoft Windows Media Center where specially crafted .MCL files can bypass security warnings to execute arbitrary code via remote shares. The PoC demonstrates RCE by using a Control Panel Shortcut to execute a CPL file from a remote location.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Windows Media Center (all versions prior to May 10th, 2016 update)
No auth needed
Prerequisites: Access to a remote share (WebDAV/SMB) · Victim interaction to open the .MCL file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Patch, Vendor Advisory vendor-advisory x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-059
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/90023
Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/39805/
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1035832
Third Party Advisory, VDB Entry x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-16-277

Scores

CVSS v3 7.8
EPSS 0.6973
EPSS Percentile 99.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-11-03
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2016-0223
Status published
Products (3)
microsoft/windows_7
microsoft/windows_8.1
microsoft/windows_vista
Published May 11, 2016
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026