SMTP: Microsoft Silverlight String Decoder Memory Corruption

This signature detects an attempt to exploit an Microsoft Silverlight application. Successful exploitation could allow an attacker to execute arbitrary code into the application's context.

Extended Description

Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka "Silverlight Runtime Remote Code Execution Vulnerability."

Affected Products

Microsoft silverlight

Short Name
SMTP:VULN:MS-SILVERLIGHT-MC
Severity
Major
Recommended
True
Recommended Action
None
Category
SMTP
Keywords
CVE-2016-0034 Corruption Decoder Memory Microsoft Silverlight String
Release Date
12/21/2017
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3415
False Positive
Unknown
Vendors

Microsoft

CVSS Score

9.3

Found a potential security threat?