CVE-2013-0074: Microsoft Silverlight Double Dereference Vulnerability

High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2022-05-25. EPSS: 78.9% chance of exploitation in the next 30 days.

Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows remote attackers to execute arbitrary code via a crafted Silverlight application, aka "Silverlight Double Dereference Vulnerability."

Affected products

  • Microsoft Silverlight: from 5.0, before 5.1.20125.0 (fixed in 5.1.20125.0)

Published 2013-03-13. Last modified 2026-08-14.