Remote Code Execution Vulnerability in Microsoft Windows Media Center
CVE-2015-6131

Currently unrated

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
9 December 2015

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC๐ŸŸฃ EPSS 59%

What is CVE-2015-6131?

A vulnerability in Microsoft Windows Media Center allows remote attackers to execute arbitrary code on vulnerable systems. By crafting a malicious .mcl file and enticing a user to open it, an attacker can gain unauthorized access and execute harmful commands. This impacts multiple versions of Microsoft Windows, including Vista, 7, 8, and 8.1.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

EPSS Score

59% chance of being exploited in the next 30 days.

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.