PT-2013-1344 · Microsoft · Silverlight
Published
2013-10-08
·
Updated
2025-03-14
·
CVE-2013-3896
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Silverlight versions prior to 5.1.20913.0
Description
The issue is related to insufficient pointer validation for accessing elements when handling objects in memory. This can be exploited by a remote attacker to gain unauthorized access to protected information by opening a specially crafted malicious link or running a specially crafted malicious application. The exploitation allows remote attackers to obtain sensitive information via a crafted Silverlight application.
Recommendations
For Microsoft Silverlight versions prior to 5.1.20913.0, update to version 5.1.20913.0 or later to resolve the issue. As a temporary workaround, consider restricting access to Silverlight elements to minimize the risk of exploitation.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Silverlight