CVE-2013-3896: Microsoft Silverlight Information Disclosure Vulnerability
Microsoft Silverlight 5 before 5.1.20913.0 does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application, aka "Silverlight Vulnerability."
Other sources
Microsoft Silverlight does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Microsoft Silverlightto a version that resolves this vulnerability.Fixed in 5.1.20913.0 - Compensating control
Disconnect Microsoft Silverlight installations from the network if still in use (product is end-of-life and should be isolated).
Event History
Frequently Asked Questions
What are the potential impacts of CVE-2013-3896?
CVE-2013-3896 allows remote attackers to obtain sensitive information through a crafted Silverlight application.
How do I mitigate the risk associated with CVE-2013-3896?
To mitigate CVE-2013-3896, upgrade Microsoft Silverlight to the latest version 5.1.20913.0 or higher.
Which versions of Silverlight are affected by CVE-2013-3896?
CVE-2013-3896 affects Microsoft Silverlight versions prior to 5.1.20913.0.
Is CVE-2013-3896 a critical vulnerability?
CVE-2013-3896 is classified as a moderate severity vulnerability based on its potential impacts.
Where can I find more information about CVE-2013-3896?
More information regarding CVE-2013-3896 can be found in Microsoft's security bulletins and incident reports.