Vulnerability record · CVE-2013-0074 · published 13 March 2013
CVE-2013-0074: Microsoft Silverlight pointer validation flaw enables remote code execution
Microsoft · Silverlight
Microsoft Silverlight 5 and the 5 Developer Runtime before 5.1.20125.0 fail to properly validate pointers during HTML object rendering. A crafted Silverlight application can trigger a double dereference, letting an attacker run arbitrary code in the context of the affected process. The product is end-of-life, so unpatched installs remain exposed.
Description
Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows remote attackers to execute arbitrary code via a crafted Silverlight application, aka "Silverlight Double Dereference Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw allows remote code execution, is in CISA KEV with known ransomware use, has very high EPSS, and affects an end-of-life product that cannot be fully remediated by patching alone.
What it is
Microsoft Silverlight 5 and the 5 Developer Runtime before 5.1.20125.0 fail to properly validate pointers during HTML object rendering. A crafted Silverlight application can trigger a double dereference, letting an attacker run arbitrary code in the context of the affected process. The product is end-of-life, so unpatched installs remain exposed.
Impact
An attacker who gets a crafted Silverlight application to render can execute arbitrary code with the privileges of the user running the browser or host process. That can lead to full compromise of the user's session and data.
Attack surface
Reached by rendering a malicious Silverlight application in a browser or host that loads the plug-in; the CVSS vector shows local access with user interaction required (UI:R) and no privileges required (PR:N). No authentication is needed, but the victim must load or view the crafted content.
Exploitation
Listed in CISA KEV since 2022-05-25 with known ransomware campaign use, and EPSS 30-day probability is about 0.81 (99.6th percentile), indicating high likelihood of exploitation activity. No public exploit details are given in the record beyond the KEV and reference tags.
What to do
- Apply Microsoft security bulletin MS13-022 to update Silverlight to 5.1.20125.0 or later where the product is still installed.
- Because Silverlight is end-of-life, disconnect or remove the plug-in from systems that no longer require it, per CISA KEV required action.
- Block Silverlight content and untrusted XAP/HTML object embedding at the browser and proxy level.
- Restrict user rights and apply least privilege so code execution does not gain administrative access.
- Inventory remaining Silverlight installations and treat them as unsupported, high-risk endpoints.
Detection
- Hunt for Silverlight process creation or browser child processes loading Silverlight content, especially from untrusted or external sites.
- Monitor for unusual code execution or memory corruption crashes originating from the Silverlight plug-in.
- Alert on Silverlight XAP or HTML object downloads from newly seen or low-reputation domains.
- Review endpoint logs for post-exploitation behavior on hosts with Silverlight installed, given known ransomware use.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2013-0074 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Microsoft Silverlight Double Dereference Vulnerability". CISA reports known use in ransomware campaigns. Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 15 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.us-cert.gov/ncas/alerts/TA13-071A | Third Party AdvisoryUS Government Resource |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-022 | PatchVendor Advisory |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16516 | Broken Link |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16565 | Broken Link |
| http://www.us-cert.gov/ncas/alerts/TA13-071A | Third Party AdvisoryUS Government Resource |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-022 | PatchVendor Advisory |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16516 | Broken Link |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16565 | Broken Link |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-0074 | US Government Resource |
Track CVE-2013-0074 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-0074), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.