CVE-2010-0019: Code Injection
Microsoft Silverlight 3 before 3.0.50611.0 on Windows, and before 3.0.41130.0 on Mac OS X, does not properly handle pointers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and framework outage) via a crafted web site, aka "Microsoft Silverlight Memory Corruption Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0019?
CVE-2010-0019 is rated as critical due to its potential to allow remote attackers to execute arbitrary code.
How do I fix CVE-2010-0019?
To fix CVE-2010-0019, update Microsoft Silverlight to version 3.0.50611.0 or later.
Which versions of Microsoft Silverlight are affected by CVE-2010-0019?
CVE-2010-0019 affects Microsoft Silverlight versions earlier than 3.0.50611.0 on Windows and 3.0.41130.0 on Mac OS X.
What are the consequences of exploiting CVE-2010-0019?
Exploiting CVE-2010-0019 can result in memory corruption and framework outages, leading to denial of service.
Is there any workaround for CVE-2010-0019?
Currently, the best mitigation for CVE-2010-0019 is to apply the available security update as there are no effective workarounds.