PT-2013-1344 · Microsoft · Silverlight

Published

2013-10-08

·

Updated

2025-03-14

·

CVE-2013-3896

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Silverlight versions prior to 5.1.20913.0
Description The issue is related to insufficient pointer validation for accessing elements when handling objects in memory. This can be exploited by a remote attacker to gain unauthorized access to protected information by opening a specially crafted malicious link or running a specially crafted malicious application. The exploitation allows remote attackers to obtain sensitive information via a crafted Silverlight application.
Recommendations For Microsoft Silverlight versions prior to 5.1.20913.0, update to version 5.1.20913.0 or later to resolve the issue. As a temporary workaround, consider restricting access to Silverlight elements to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03495
CVE-2013-3896

Affected Products

Silverlight