CVE-2015-6166: Microsoft Silverlight

High severity, CVSS 9.3. EPSS: 14.1% chance of exploitation in the next 30 days.

Microsoft Silverlight 5 before 5.1.41105.00 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read or write access) via unspecified open and close requests, aka "Microsoft Silverlight RCE Vulnerability."

Affected products

Published 2015-12-09. Last modified 2026-06-17.