← Vulnerability feed

Vulnerability record · CVE-2013-0074 · published 13 March 2013

CVE-2013-0074: Microsoft Silverlight pointer validation flaw enables remote code execution

Microsoft · Silverlight

Microsoft Silverlight 5 and the 5 Developer Runtime before 5.1.20125.0 fail to properly validate pointers during HTML object rendering. A crafted Silverlight application can trigger a double dereference, letting an attacker run arbitrary code in the context of the affected process. The product is end-of-life, so unpatched installs remain exposed.

7.8 CVSS 3.1 High CISA KEV since 25 May 2022 Known ransomware use EPSS 79% · top 0.4%
7.8CVSS 3.1 base score, v2 9.3
79%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
9References
14 Aug 2026Last modified by NVD

Description

Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows remote attackers to execute arbitrary code via a crafted Silverlight application, aka "Silverlight Double Dereference Vulnerability."

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw allows remote code execution, is in CISA KEV with known ransomware use, has very high EPSS, and affects an end-of-life product that cannot be fully remediated by patching alone.

What it is

Microsoft Silverlight 5 and the 5 Developer Runtime before 5.1.20125.0 fail to properly validate pointers during HTML object rendering. A crafted Silverlight application can trigger a double dereference, letting an attacker run arbitrary code in the context of the affected process. The product is end-of-life, so unpatched installs remain exposed.

Impact

An attacker who gets a crafted Silverlight application to render can execute arbitrary code with the privileges of the user running the browser or host process. That can lead to full compromise of the user's session and data.

Attack surface

Reached by rendering a malicious Silverlight application in a browser or host that loads the plug-in; the CVSS vector shows local access with user interaction required (UI:R) and no privileges required (PR:N). No authentication is needed, but the victim must load or view the crafted content.

Exploitation

Listed in CISA KEV since 2022-05-25 with known ransomware campaign use, and EPSS 30-day probability is about 0.81 (99.6th percentile), indicating high likelihood of exploitation activity. No public exploit details are given in the record beyond the KEV and reference tags.

What to do

  • Apply Microsoft security bulletin MS13-022 to update Silverlight to 5.1.20125.0 or later where the product is still installed.
  • Because Silverlight is end-of-life, disconnect or remove the plug-in from systems that no longer require it, per CISA KEV required action.
  • Block Silverlight content and untrusted XAP/HTML object embedding at the browser and proxy level.
  • Restrict user rights and apply least privilege so code execution does not gain administrative access.
  • Inventory remaining Silverlight installations and treat them as unsupported, high-risk endpoints.

Detection

  • Hunt for Silverlight process creation or browser child processes loading Silverlight content, especially from untrusted or external sites.
  • Monitor for unusual code execution or memory corruption crashes originating from the Silverlight plug-in.
  • Alert on Silverlight XAP or HTML object downloads from newly seen or low-reputation domains.
  • Review endpoint logs for post-exploitation behavior on hosts with Silverlight installed, given known ransomware use.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2013-0074 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Microsoft Silverlight Double Dereference Vulnerability". CISA reports known use in ransomware campaigns. Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 15 June 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-0074 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2016-0034Microsoft Silverlight negative offset decoding flaw allows remote code executionMicrosoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, corrupting object headers. A remote attacker can exploit this…KEVEPSS 69%analysed7.8CVE-2015-1671Microsoft DirectWrite TrueType Font Parsing Remote Code ExecutionThe Windows DirectWrite library fails to properly handle crafted TrueType fonts, allowing memory corruption that can lead to arbitrary code execution…KEVEPSS 49%analysed5.5CVE-2013-3896Microsoft Silverlight pointer validation flaw leaks sensitive informationMicrosoft Silverlight 5 before 5.1.20913.0 fails to properly validate pointers during access to Silverlight elements, allowing a crafted Silverlight …KEVEPSS 68%analysed9.3CVE-2015-6166Microsoft silverlight memory buffer overflow vulnerabilityMicrosoft Silverlight 5 before 5.1.41105.00 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read or wri…EPSS 14%9.3CVE-2015-6108Microsoft live meeting memory buffer overflow vulnerabilityThe Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8; Windows 8.1; Windows Server 20…EPSS 26%9.3CVE-2015-2464Microsoft .net framework improper input validation vulnerabilityMicrosoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT G…EPSS 36%9.3CVE-2015-2463Microsoft .net framework improper input validation vulnerabilityMicrosoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT G…EPSS 34%9.3CVE-2015-2456Microsoft .net framework improper input validation vulnerabilityMicrosoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT G…EPSS 36%

Source: NIST National Vulnerability Database (record CVE-2013-0074), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.