CVE-2013-0074

KEV
Published: Mar 13, 2013 Last Modified: Ott 22, 2025
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,8
Attack Vector: local
Attack Complexity: low
Privileges Required: none
User Interaction: required
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
HIGH 9,3
Access Vector: network
Access Complexity: medium
Authentication: none
Confidentiality: complete
Integrity: complete
Availability: complete

Description

AI Translation Available

Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows remote attackers to execute arbitrary code via a crafted Silverlight application, aka 'Silverlight Double Dereference Vulnerability.'

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,9305
Percentile
1,0th
Updated

EPSS Score Trend (Last 91 Days)

Exploit

Microsoft Internet Explorer - COALineDashStyleArray Unsafe Memory Access …

Verified Metasploit Framework (MSF)

Microsoft Internet Explorer - COALineDashStyleArray Unsafe Memory Access (MS12-022) (Metasploit)

View Exploit Code →
Exploit

Microsoft Silverlight - ScriptObject Unsafe Memory Access (MS13-022/MS13-087) …

Verified

Microsoft Silverlight - ScriptObject Unsafe Memory Access (MS13-022/MS13-087) (Metasploit)

View Exploit Code →
Application

Silverlight by Microsoft

Version Range Affected
From 5.0 (inclusive)
To 5.1.20125.0 (exclusive)
cpe:2.3:a:microsoft:silverlight:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013…
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-0…
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%…
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%…
http://www.us-cert.gov/ncas/alerts/TA13-071A
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-0…
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%…
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%…
http://www.us-cert.gov/ncas/alerts/TA13-071A