CVE-2013-3896: Microsoft Silverlight Information Disclosure Vulnerability

Medium severity, CVSS 5.5. Actively exploited: in CISA KEV since 2022-05-25. EPSS: 68% chance of exploitation in the next 30 days.

Microsoft Silverlight 5 before 5.1.20913.0 does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application, aka "Silverlight Vulnerability."

Affected products

  • Microsoft Silverlight: from 5.0, before 5.1.20913.0 (fixed in 5.1.20913.0)

Published 2013-10-09. Last modified 2026-06-16.