← Vulnerability feed

Vulnerability record · CVE-2013-3896 · published 9 October 2013

CVE-2013-3896: Microsoft Silverlight pointer validation flaw leaks sensitive information

Microsoft · Silverlight

Microsoft Silverlight 5 before 5.1.20913.0 fails to properly validate pointers during access to Silverlight elements, allowing a crafted Silverlight application to disclose sensitive information. The flaw is fixed in MS13-087, but Silverlight is end-of-life, so unpatched or unpatchable hosts remain exposed.

5.5 CVSS 3.1 Medium CISA KEV since 25 May 2022 EPSS 68% · top 0.7%
5.5CVSS 3.1 base score, v2 4.3
68%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
9References
16 Jun 2026Last modified by NVD

Description

Microsoft Silverlight 5 before 5.1.20913.0 does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application, aka "Silverlight Vulnerability."

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw is in CISA KEV with very high EPSS and affects an end-of-life product, but impact is limited to information disclosure with required user interaction.

What it is

Microsoft Silverlight 5 before 5.1.20913.0 fails to properly validate pointers during access to Silverlight elements, allowing a crafted Silverlight application to disclose sensitive information. The flaw is fixed in MS13-087, but Silverlight is end-of-life, so unpatched or unpatchable hosts remain exposed.

Impact

An attacker can read sensitive information from the affected process memory, potentially exposing data that aids further compromise. There is no integrity or availability impact per the CVSS vector.

Attack surface

Reached by a user opening a crafted Silverlight application; the CVSS vector (AV:L, UI:R, PR:N) indicates local access with user interaction and no authentication required.

Exploitation

CVE-2013-3896 is listed in CISA KEV (added 2022-05-25) and has a high EPSS 30-day probability of 0.6961 (99.3rd percentile), indicating observed exploitation activity.

What to do

  • Apply Microsoft security bulletin MS13-087 to update Silverlight to 5.1.20913.0 or later where still supported.
  • Because Silverlight is end-of-life, disconnect or remove Silverlight from systems where it is no longer required, per CISA KEV required action.
  • Block or restrict execution of untrusted Silverlight content and disable the Silverlight browser plug-in where feasible.
  • Restrict user ability to launch untrusted applications or content from external sources.

Detection

  • Monitor for Silverlight process (e.g., npctrl.dll / Silverlight) loading or executing content from untrusted or unusual paths.
  • Hunt for suspicious Silverlight application launches correlated with outbound network activity or file writes.
  • Review endpoint logs for Silverlight version strings below 5.1.20913.0 to identify unpatched hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2013-3896 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Microsoft Silverlight Information Disclosure Vulnerability". Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 15 June 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-3896 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2016-0034Microsoft Silverlight negative offset decoding flaw allows remote code executionMicrosoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, corrupting object headers. A remote attacker can exploit this…KEVEPSS 69%analysed7.8CVE-2015-1671Microsoft DirectWrite TrueType Font Parsing Remote Code ExecutionThe Windows DirectWrite library fails to properly handle crafted TrueType fonts, allowing memory corruption that can lead to arbitrary code execution…KEVEPSS 49%analysed7.8CVE-2013-0074Microsoft Silverlight pointer validation flaw enables remote code executionMicrosoft Silverlight 5 and the 5 Developer Runtime before 5.1.20125.0 fail to properly validate pointers during HTML object rendering. A crafted Sil…KEVEPSS 79%analysed9.3CVE-2015-6166Microsoft silverlight memory buffer overflow vulnerabilityMicrosoft Silverlight 5 before 5.1.41105.00 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read or wri…EPSS 14%9.3CVE-2015-6108Microsoft live meeting memory buffer overflow vulnerabilityThe Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8; Windows 8.1; Windows Server 20…EPSS 26%9.3CVE-2015-2464Microsoft .net framework improper input validation vulnerabilityMicrosoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT G…EPSS 36%9.3CVE-2015-2463Microsoft .net framework improper input validation vulnerabilityMicrosoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT G…EPSS 34%9.3CVE-2015-2456Microsoft .net framework improper input validation vulnerabilityMicrosoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT G…EPSS 36%

Source: NIST National Vulnerability Database (record CVE-2013-3896), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.