PT-2013-1344 · Microsoft · Silverlight
Publicado
2013-10-08
·
Atualizado
2025-03-14
·
CVE-2013-3896
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Silverlight versions prior to 5.1.20913.0
Description
The issue is related to insufficient pointer validation for accessing elements when handling objects in memory. This can be exploited by a remote attacker to gain unauthorized access to protected information by opening a specially crafted malicious link or running a specially crafted malicious application. The exploitation allows remote attackers to obtain sensitive information via a crafted Silverlight application.
Recommendations
For Microsoft Silverlight versions prior to 5.1.20913.0, update to version 5.1.20913.0 or later to resolve the issue. As a temporary workaround, consider restricting access to Silverlight elements to minimize the risk of exploitation.
Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Silverlight