Junglewise Threat Intelligence

CVE-2013-0074: Microsoft Silverlight Double Dereference Vulnerability

CVE-2013-0074 · Severity: critical · CVSS 9.3 · Exploited in the wild · Published 2022-05-25

Technologies: Microsoft Silverlight. Vendors: Microsoft.

Executive brief

Microsoft Silverlight fails to properly validate pointers during HTML object rendering. This double dereference vulnerability allows remote attackers to execute arbitrary code via a specially crafted Silverlight application.

Affected products

  • Microsoft Silverlight 5 before 5.1.20125.0
  • Microsoft Silverlight 5 Developer Runtime before 5.1.20125.0

Timeline

  • 2013-03-12: advisory: Microsoft Security Bulletin MS13-022 published
  • 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-05-25: exploited: Confirmed exploited in the wild per CISA KEV catalog entry

Related threats