Junglewise Threat Intelligence

CVE-2013-3896: Microsoft Silverlight Information Disclosure Vulnerability

CVE-2013-3896 · Severity: critical · CVSS 5.5 · Exploited in the wild · Published 2022-05-25

Technologies: Microsoft Silverlight. Vendors: Microsoft.

Executive brief

Microsoft Silverlight fails to properly validate pointers when accessing Silverlight elements. A remote attacker can exploit this by providing a crafted Silverlight application to obtain sensitive information from the memory of the affected system.

Affected products

  • Microsoft Silverlight 5 before 5.1.20913.0

Timeline

  • 2013-10-09: disclosed: Initial CVE analysis date
  • 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2013-10-08: patched: Microsoft Security Bulletin MS13-087 released

Related threats