CVE-2013-3896
KEVmassInformation Disclosure in Microsoft Silverlight via Improper Pointer Validation
CISA: Microsoft Silverlight Information Disclosure Vulnerability
CVE-2013-3896 is an information-disclosure flaw in Microsoft Silverlight caused by improper input validation (CWE-20): Silverlight does not correctly validate pointers when accessing Silverlight elements. An attacker triggers it by inducing a user to run a crafted Silverlight application, typically delivered through a malicious or compromised web page. Successful exploitation allows the attacker to obtain sensitive information from the affected system, though the flaw does not provide code execution. All deployments of Microsoft Silverlight are affected, and the product is now end-of-life per CISA. The flaw is listed in the CISA KEV catalog (added 2022-05-25) and carries a high probability of exploitation (EPSS 69.6%, 99th percentile), with ransomware use listed as unknown; no public PoC is known.
What to do: Because Microsoft Silverlight is end-of-life, CISA's required action is to disconnect or retire any systems still using it; the cleanest fix is to uninstall the Silverlight runtime where it is no longer needed. If Silverlight must remain on legacy systems, apply Microsoft's October 2013 Patch Tuesday Silverlight security update (released the same cycle as the IE zero-day fixes). Audit endpoints and web apps for Silverlight dependencies, and treat any remaining Silverlight-enabled browsing paths as legacy risk.
| Microsoft Silverlight | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Silverlight does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application.
- Affected
- Microsoft Silverlight
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
- Due date
- Ransomware use
- Unknown
- Vendors
- Microsoft
- Products
- Silverlight
- Weakness
- CWE-20