KEV · Actively exploited
CVE-2016-0185
CVE-2016-0185 is actively exploited (CISA KEV catalog) : high severity (CVSS 7.8), 0 tracked apps concerned, none still exposed on their current version.
- Severity (CVSS)
- 7.8
- Exploitation
- Confirmed
- Tracked apps
- 0
- Still exposed
- 0
NVD scale
CISA KEV · EPSS predicts 69.9 %
Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted Media Center link (aka .mcl) file, aka "Windows Media Center Remote Code Execution Vulnerability."
Attack vector : Local
No privileges required
Show raw CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
69.94%
predictive model; CISA confirms active exploitation
percentile 99.3%
CISA Known Exploited Vulnerability
- Added to KEV
- 2021-11-03
- Remediation deadline
- 2022-05-03
- Required action
- Apply updates per vendor instructions.
- Ransomware
- Unknown (not documented by CISA)