RULE(RULE ID:316552)

Rule General Information
Release Date: 2016-07-27
Rule Name: FILE-OTHER Microsoft Silverlight String Decoder Memory Corruption Vulnerability -2 (CVE-2016-0034)
Severity:
CVE ID:
Rule Protection Details
Description: Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka "Silverlight Runtime Remote Code Execution Vulnerability."
Impact: An attacker can execute arbitrary code in the context of the vulnerable system. Failed exploit may cause denial-of-service attack.
Affected OS: Windows
Reference: MicrosoftSecurityBulletin:MS16-006
SecurityTrackerID:1034655
Solutions
Microsoft has released a patch MS16-006 to eliminate the vulnerability. The patch can be downloaded at http://technet.microsoft.com/security/bulletin/MS16-006