PT-2013-1344 · Microsoft · Silverlight

Publicado

2013-10-08

·

Atualizado

2025-03-14

·

CVE-2013-3896

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Silverlight versions prior to 5.1.20913.0
Description The issue is related to insufficient pointer validation for accessing elements when handling objects in memory. This can be exploited by a remote attacker to gain unauthorized access to protected information by opening a specially crafted malicious link or running a specially crafted malicious application. The exploitation allows remote attackers to obtain sensitive information via a crafted Silverlight application.
Recommendations For Microsoft Silverlight versions prior to 5.1.20913.0, update to version 5.1.20913.0 or later to resolve the issue. As a temporary workaround, consider restricting access to Silverlight elements to minimize the risk of exploitation.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-03495
CVE-2013-3896

Produtos afetados

Silverlight