ZeroHour

CVE-2016-0185

KEVmass

Remote Code Execution in Windows Media Center (.mcl) on Windows Vista, 7, and 8.1

CISA: Microsoft Windows Media Center Remote Code Execution Vulnerability

CVSS 3.1
7.8 high
EPSS
70%p99
Published
()
KEV added
AI analysis

Windows Media Center in Windows Vista SP2, Windows 7 SP1, and Windows 8.1 mishandles crafted Media Center link (.mcl) files, allowing arbitrary code execution. An attacker must craft a malicious .mcl file and get a user to open it: despite the vulnerability's name, the CVSS vector shows a local attack vector with user interaction required, so it behaves like a malicious-file attack rather than a wormable network-service exploit. Successful exploitation gives the attacker code execution in the context of the signed-in user, with high impact on confidentiality, integrity, and availability. Any user of the affected Windows versions on which the Media Center component is installed is exposed. CISA added the flaw to the KEV on 2021-11-03, confirming real-world exploitation (ransomware use unknown), and its EPSS of ~70% probability of exploitation in 30 days sits in the 99th percentile; no public PoC is known.

What to do: Apply the Microsoft security update for Windows Media Center (addressed in the May 2016 Patch Tuesday releases) on all Windows Vista SP2, Windows 7 SP1, and Windows 8.1 systems, per CISA's KEV required action, prioritizing endpoints whose users open .mcl files. Because these Windows versions are at or past end of support, plan migration for any systems that remain unpatched. Until patched, advise users not to open unsolicited or web-delivered .mcl files and inventory legacy endpoints to confirm whether Windows Media Center is installed or in use.

Affected
Microsoft Windows VistaSP2 (systems with Windows Media Center)
Microsoft Windows 7SP1 (systems with Windows Media Center)
Microsoft Windows 8.1affected releases (systems with the Windows Media Center component)
Estimated exposure
masspotentially tens of millions+ of legacy Windows PCs with Media Center present (Windows 7/8.1/Vista installed base ran into the hundreds of millions) — Windows 7 and 8.1 shipped to hundreds of millions of devices and Windows 7 retained a very large installed base after its 2020 end of support, but Windows Media Center is an edition-dependent/optional component and there are no public…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted Media Center link (aka .mcl) file, aka "Windows Media Center Remote Code Execution Vulnerability."

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 7, windows 8.1, windows vista
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news