Skip to content
COOEY

EXPOSURES › CVE-2013-3896

CVE-2013-3896

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-05-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2013-3896 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

A legacy Microsoft Silverlight vulnerability (CVE-2013-3896) allowed remote attackers to extract sensitive data via pointer validation flaws.

Microsoft Silverlight, a discontinued platform, suffered an information disclosure flaw where improper pointer validation let attackers read sensitive data. DIBs must care because legacy software like this is often left unpatched, creating long-standing exposure to known exploits. The takeaway is to retire unsupported platforms and patch known CVEs before they hit the KEV list.

Shame score — A known, unpatched vulnerability in legacy software that was actively exploited in the wild, showing negligence in maintaining outdated platforms.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Silverlight does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application.

AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized