CVE-2013-3896CISA KEV
Microsoft Silverlight Information Disclosure Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Silverlight does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application.
- Product
- Silverlight
- Added to KEV
- 25 May 2022
- Federal remediation due
- 15 Jun 2022
- Known ransomware use
- Not reported