CVE-2013-3178: Code Injection
Microsoft Silverlight 5 before 5.1.20513.0 does not properly initialize arrays, which allows remote attackers to execute arbitrary code or cause a denial of service (NULL pointer dereference) via a crafted Silverlight application, aka "Null Pointer Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3178?
CVE-2013-3178 is rated as critical due to its potential to allow remote code execution.
How do I fix CVE-2013-3178?
To fix CVE-2013-3178, you should upgrade Microsoft Silverlight to version 5.1.20513.0 or later.
What types of attacks can exploit CVE-2013-3178?
CVE-2013-3178 can be exploited using crafted Silverlight applications to execute arbitrary code or cause a denial of service.
Which versions of Silverlight are affected by CVE-2013-3178?
CVE-2013-3178 affects Microsoft Silverlight versions 5.0.60401.0 to 5.1.20125.0.
Is there a workaround for CVE-2013-3178?
There is no known workaround for CVE-2013-3178, so it is recommended to apply the patch immediately.