CVE-2016-0185
KEVmassRemote Code Execution in Windows Media Center (.mcl) on Windows Vista, 7, and 8.1
CISA: Microsoft Windows Media Center Remote Code Execution Vulnerability
Windows Media Center in Windows Vista SP2, Windows 7 SP1, and Windows 8.1 mishandles crafted Media Center link (.mcl) files, allowing arbitrary code execution. An attacker must craft a malicious .mcl file and get a user to open it: despite the vulnerability's name, the CVSS vector shows a local attack vector with user interaction required, so it behaves like a malicious-file attack rather than a wormable network-service exploit. Successful exploitation gives the attacker code execution in the context of the signed-in user, with high impact on confidentiality, integrity, and availability. Any user of the affected Windows versions on which the Media Center component is installed is exposed. CISA added the flaw to the KEV on 2021-11-03, confirming real-world exploitation (ransomware use unknown), and its EPSS of ~70% probability of exploitation in 30 days sits in the 99th percentile; no public PoC is known.
What to do: Apply the Microsoft security update for Windows Media Center (addressed in the May 2016 Patch Tuesday releases) on all Windows Vista SP2, Windows 7 SP1, and Windows 8.1 systems, per CISA's KEV required action, prioritizing endpoints whose users open .mcl files. Because these Windows versions are at or past end of support, plan migration for any systems that remain unpatched. Until patched, advise users not to open unsolicited or web-delivered .mcl files and inventory legacy endpoints to confirm whether Windows Media Center is installed or in use.
| Microsoft Windows Vista | SP2 (systems with Windows Media Center) |
| Microsoft Windows 7 | SP1 (systems with Windows Media Center) |
| Microsoft Windows 8.1 | affected releases (systems with the Windows Media Center component) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted Media Center link (aka .mcl) file, aka "Windows Media Center Remote Code Execution Vulnerability."
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 7, windows 8.1, windows vista
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H