⚠ Actively exploited
Added to CISA KEV on 2022-05-25. Federal agencies required to patch by 2022-06-15. Required action: The impacted product is end-of-life and should be disconnected if still in use..
CVE-2013-3896
Severity
5.5MEDIUM
EPSS
81.6%
top 0.82%
CISA KEV
KEV
Added 2022-05-25
Due 2022-06-15
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedOct 9
KEV addedMay 25
KEV dueJun 15
CISA Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Description
Microsoft Silverlight 5 before 5.1.20913.0 does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application, aka "Silverlight Vulnerability."
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6
Affected Packages1 packages
Patches
🔴Vulnerability Details
3💥Exploits & PoCs
1Exploit-DB▶
Microsoft Silverlight - ScriptObject Unsafe Memory Access (MS13-022/MS13-087) (Metasploit)↗2013-03-12