CVE-2013-3896
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
The impacted product is end-of-life and should be disconnected if still in use.
Microsoft Silverlight 5 fails to properly check memory pointers when accessing elements, allowing attackers to read sensitive information by tricking users into running a malicious Silverlight application.
A pointer validation vulnerability in Microsoft Silverlight 5 (before 5.1.20913.0) permits remote code execution context to leak sensitive memory information through a crafted application. The attack vector requires user interaction to load and execute the malicious Silverlight content; impact is confidentiality breach without requiring elevated privileges.
The full analysis of this CVE is available in Portuguese →