CVE-2016-0185
HIGH KEVMicrosoft Windows Media Center - Remote Code Execution via Crafted MCL File
Title source: llmExploitation Summary
CVE-2016-0185 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021. EIP tracks 1 public exploit from researchers including Eduardo Braun Prado.
AI-analyzed exploit summary This exploit leverages a vulnerability in Microsoft Windows Media Center where specially crafted .MCL files can bypass security warnings to execute arbitrary code via remote shares. The PoC demonstrates RCE by using a Control Panel Shortcut to execute a CPL file from a remote location.
Description
Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted Media Center link (aka .mcl) file, aka "Windows Media Center Remote Code Execution Vulnerability."
Exploits (1)
This exploit leverages a vulnerability in Microsoft Windows Media Center where specially crafted .MCL files can bypass security warnings to execute arbitrary code via remote shares. The PoC demonstrates RCE by using a Control Panel Shortcut to execute a CPL file from a remote location.
References (6)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H