CVE-2016-0185: Microsoft Windows Media Center Remote Code Execution Vulnerability
High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 69.8% chance of exploitation in the next 30 days.
Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted Media Center link (aka .mcl) file, aka "Windows Media Center Remote Code Execution Vulnerability."
Affected products
- Microsoft Windows 7: affected versions not specified
- Microsoft Windows 8.1: affected versions not specified
- Microsoft Windows Vista: affected versions not specified
Published 2016-05-11. Last modified 2026-06-17.