ZeroHour

CVE-2013-3896

KEVmass

Information Disclosure in Microsoft Silverlight via Improper Pointer Validation

CISA: Microsoft Silverlight Information Disclosure Vulnerability

CVSS
EPSS
70%p99
Published
KEV added
AI analysis

CVE-2013-3896 is an information-disclosure flaw in Microsoft Silverlight caused by improper input validation (CWE-20): Silverlight does not correctly validate pointers when accessing Silverlight elements. An attacker triggers it by inducing a user to run a crafted Silverlight application, typically delivered through a malicious or compromised web page. Successful exploitation allows the attacker to obtain sensitive information from the affected system, though the flaw does not provide code execution. All deployments of Microsoft Silverlight are affected, and the product is now end-of-life per CISA. The flaw is listed in the CISA KEV catalog (added 2022-05-25) and carries a high probability of exploitation (EPSS 69.6%, 99th percentile), with ransomware use listed as unknown; no public PoC is known.

What to do: Because Microsoft Silverlight is end-of-life, CISA's required action is to disconnect or retire any systems still using it; the cleanest fix is to uninstall the Silverlight runtime where it is no longer needed. If Silverlight must remain on legacy systems, apply Microsoft's October 2013 Patch Tuesday Silverlight security update (released the same cycle as the IE zero-day fixes). Audit endpoints and web apps for Silverlight dependencies, and treat any remaining Silverlight-enabled browsing paths as legacy risk.

Affected
Microsoft Silverlight
Estimated exposure
masstens of millions of legacy Windows endpoints historically had Silverlight installed (peak install base in the hundreds of millions), though actively… — Silverlight was broadly distributed via Windows Update to hundreds of millions of PCs at its peak, but modern browsers dropped plugin support and the product is end-of-life, so current exposure is concentrated in legacy enterprise Windows…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Silverlight does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application.

CISA Known Exploited Vulnerability
Affected
Microsoft Silverlight
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Silverlight
Weakness
CWE-20

In the news