First published: Wed Aug 11 2010(Updated: )
Microsoft Silverlight 3 before 3.0.50611.0 on Windows, and before 3.0.41130.0 on Mac OS X, does not properly handle pointers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and framework outage) via a crafted web site, aka "Microsoft Silverlight Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Silverlight | <=3.0.40818.0 | |
Microsoft Silverlight | =3.0.40624.00 | |
Microsoft Silverlight | =3.0.40723.0 | |
Apple iOS and macOS | ||
Microsoft Silverlight | <=3.0.50106.0 | |
Microsoft Silverlight | =3.0.40818.0 | |
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0019 is rated as critical due to its potential to allow remote attackers to execute arbitrary code.
To fix CVE-2010-0019, update Microsoft Silverlight to version 3.0.50611.0 or later.
CVE-2010-0019 affects Microsoft Silverlight versions earlier than 3.0.50611.0 on Windows and 3.0.41130.0 on Mac OS X.
Exploiting CVE-2010-0019 can result in memory corruption and framework outages, leading to denial of service.
Currently, the best mitigation for CVE-2010-0019 is to apply the available security update as there are no effective workarounds.