ZeroHour

CVE-2013-0074

KEV ransomwarelarge

Pointer-Validation RCE in Microsoft Silverlight (KEV-listed, EOL)

CISA: Microsoft Silverlight Double Dereference Vulnerability

CVSS
EPSS
81%p100
Published
KEV added
AI analysis

CVE-2013-0074 is a double dereference (dangling pointer) flaw in Microsoft Silverlight: the runtime does not properly validate pointers while rendering HTML objects, corrupting memory when a malformed pointer is dereferenced. An attacker triggers it by getting a user to view a web page or open content that loads a crafted Silverlight application, with no authentication or special privileges required. Successful exploitation allows remote code execution in the context of the logged-on user, potentially letting an attacker install programs, steal data, or create accounts. Any system with the Silverlight runtime installed is affected; per CISA's required action the product is end-of-life (Silverlight support ended in October 2021) and should be disconnected if still in use. Exploitation is confirmed: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-25 with known ransomware use, and EPSS puts its 30-day exploitation probability at 81% (100th percentile), despite the absence of a known public PoC.

What to do: Audit inventories and endpoints for any Silverlight runtime or .xap-consuming applications and remove/uninstall the plugin where possible; if the runtime must be retained, ensure the March 2013 MS13-022 security update or a later Silverlight 5.1 runtime is installed. Because Silverlight is end-of-life with no further patches, follow CISA's required action: disconnect or retire any remaining Silverlight-dependent applications, and block known exploit-kit delivery vectors (drive-by web content) with updated browser and email filtering.

Affected
Microsoft SilverlightAll Silverlight versions per CISA data; no specific version range was provided (fixed by the March 2013 MS13-022 update; product now end-of-life)
Estimated exposure
largelikely hundreds of thousands of remaining legacy installs worldwide (Silverlight was once on a large share of Windows browsers; no current public scan counts) — Silverlight was historically ubiquitous on Windows browsers and remains embedded in legacy line-of-business web apps, but with the product end-of-life since October 2021 the residual active base is best estimated at the 100k–1M order…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application.

CISA Known Exploited Vulnerability
Affected
Microsoft Silverlight
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Known
Vendors
Microsoft
Products
Silverlight

In the news