PT-2014-1683 · Microsoft · Silverlight 5 Developer Runtime+1

Published

2014-03-11

·

Updated

2018-10-12

·

CVE-2014-0319

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Silverlight versions 5 through 5.1.30214.0 Microsoft Silverlight 5 Developer Runtime versions 5 through 5.1.30214.0
Description The issue exists due to the incorrect implementation of Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR) in the Silverlight security feature. This allows an attacker to bypass DEP/ASLR protection mechanisms, enabling remote execution of arbitrary code.
Recommendations For Microsoft Silverlight versions 5 through 5.1.30214.0, update to version 5.1.30214.0 or later. For Microsoft Silverlight 5 Developer Runtime versions 5 through 5.1.30214.0, update to version 5.1.30214.0 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-00630
CVE-2014-0319

Affected Products

Silverlight
Silverlight 5 Developer Runtime