CVE-2013-0074: Microsoft Silverlight Double Dereference Vulnerability
High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2022-05-25. EPSS: 78.9% chance of exploitation in the next 30 days.
Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows remote attackers to execute arbitrary code via a crafted Silverlight application, aka "Silverlight Double Dereference Vulnerability."
Affected products
- Microsoft Silverlight: from 5.0, before 5.1.20125.0 (fixed in 5.1.20125.0)
Published 2013-03-13. Last modified 2026-08-14.