Vulnerability record · CVE-2013-3896 · published 9 October 2013
CVE-2013-3896: Microsoft Silverlight pointer validation flaw leaks sensitive information
Microsoft · Silverlight
Microsoft Silverlight 5 before 5.1.20913.0 fails to properly validate pointers during access to Silverlight elements, allowing a crafted Silverlight application to disclose sensitive information. The flaw is fixed in MS13-087, but Silverlight is end-of-life, so unpatched or unpatchable hosts remain exposed.
Description
Microsoft Silverlight 5 before 5.1.20913.0 does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application, aka "Silverlight Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Automated analysis
high priorityThe flaw is in CISA KEV with very high EPSS and affects an end-of-life product, but impact is limited to information disclosure with required user interaction.
What it is
Microsoft Silverlight 5 before 5.1.20913.0 fails to properly validate pointers during access to Silverlight elements, allowing a crafted Silverlight application to disclose sensitive information. The flaw is fixed in MS13-087, but Silverlight is end-of-life, so unpatched or unpatchable hosts remain exposed.
Impact
An attacker can read sensitive information from the affected process memory, potentially exposing data that aids further compromise. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reached by a user opening a crafted Silverlight application; the CVSS vector (AV:L, UI:R, PR:N) indicates local access with user interaction and no authentication required.
Exploitation
CVE-2013-3896 is listed in CISA KEV (added 2022-05-25) and has a high EPSS 30-day probability of 0.6961 (99.3rd percentile), indicating observed exploitation activity.
What to do
- Apply Microsoft security bulletin MS13-087 to update Silverlight to 5.1.20913.0 or later where still supported.
- Because Silverlight is end-of-life, disconnect or remove Silverlight from systems where it is no longer required, per CISA KEV required action.
- Block or restrict execution of untrusted Silverlight content and disable the Silverlight browser plug-in where feasible.
- Restrict user ability to launch untrusted applications or content from external sources.
Detection
- Monitor for Silverlight process (e.g., npctrl.dll / Silverlight) loading or executing content from untrusted or unusual paths.
- Hunt for suspicious Silverlight application launches correlated with outbound network activity or file writes.
- Review endpoint logs for Silverlight version strings below 5.1.20913.0 to identify unpatched hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2013-3896 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Microsoft Silverlight Information Disclosure Vulnerability". Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 15 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.us-cert.gov/ncas/alerts/TA13-288A | Third Party AdvisoryUS Government Resource |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-087 | PatchVendor Advisory |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19003 | Broken Link |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19055 | Broken Link |
| http://www.us-cert.gov/ncas/alerts/TA13-288A | Third Party AdvisoryUS Government Resource |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-087 | PatchVendor Advisory |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19003 | Broken Link |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19055 | Broken Link |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-3896 | US Government Resource |
Track CVE-2013-3896 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-3896), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.