CVE-2013-0074
Description
Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows remote attackers to execute arbitrary code via a crafted Silverlight application, aka "Silverlight Double Dereference Vulnerability."
In plain language
AI Act nowCVE-2013-0074 is a serious security flaw in Microsoft Silverlight that could let an attacker run code from a malicious Silverlight/HTML page, so a typical small business should address it immediately if you still have Silverlight in use—especially since it’s end-of-life.
CVE-2013-0074 is a remote code execution issue in Microsoft Silverlight 5 (and 5 Developer Runtime) via improper pointer validation during HTML object rendering of a crafted Silverlight application; CISA lists it as exploited in ransomware campaigns, and the product is end-of-life.
What to do now
- Check whether Microsoft Silverlight is installed and in use on any business devices (browsers, kiosks, line-of-business apps, or internal web portals).
- If Silverlight is still in use, remove it or disconnect the affected systems from the network.
- If you have a supported reason to keep it temporarily, update Microsoft Silverlight to 5.1.20125.0 (or later) as the fixed version.
- Confirm the update took effect by re-checking installed Silverlight versions and then scan/monitor for unusual Silverlight activity in browser and system logs.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: The impacted product is end-of-life and should be disconnected if still in use.
References
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2013-0074 and every CVE in our database. Create a free account — no credit card required.
Create Free Account