CVE-2013-0074
KEV ransomwarelargePointer-Validation RCE in Microsoft Silverlight (KEV-listed, EOL)
CISA: Microsoft Silverlight Double Dereference Vulnerability
CVE-2013-0074 is a double dereference (dangling pointer) flaw in Microsoft Silverlight: the runtime does not properly validate pointers while rendering HTML objects, corrupting memory when a malformed pointer is dereferenced. An attacker triggers it by getting a user to view a web page or open content that loads a crafted Silverlight application, with no authentication or special privileges required. Successful exploitation allows remote code execution in the context of the logged-on user, potentially letting an attacker install programs, steal data, or create accounts. Any system with the Silverlight runtime installed is affected; per CISA's required action the product is end-of-life (Silverlight support ended in October 2021) and should be disconnected if still in use. Exploitation is confirmed: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-25 with known ransomware use, and EPSS puts its 30-day exploitation probability at 81% (100th percentile), despite the absence of a known public PoC.
What to do: Audit inventories and endpoints for any Silverlight runtime or .xap-consuming applications and remove/uninstall the plugin where possible; if the runtime must be retained, ensure the March 2013 MS13-022 security update or a later Silverlight 5.1 runtime is installed. Because Silverlight is end-of-life with no further patches, follow CISA's required action: disconnect or retire any remaining Silverlight-dependent applications, and block known exploit-kit delivery vectors (drive-by web content) with updated browser and email filtering.
| Microsoft Silverlight | All Silverlight versions per CISA data; no specific version range was provided (fixed by the March 2013 MS13-022 update; product now end-of-life) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application.
- Affected
- Microsoft Silverlight
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
- Due date
- Ransomware use
- Known
- Vendors
- Microsoft
- Products
- Silverlight