CVE-2013-0074

HIGH(7.8)KEVRansomwareLikely Exploited

Microsoft Silverlight Double Dereference Vulnerability

Description

CVE-2013-0074 is a remote code execution vulnerability in Microsoft Silverlight caused by improper pointer validation during HTML object rendering. A remote attacker can exploit this flaw through a crafted Silverlight application to execute arbitrary code on the affected system with the privileges of the current user. This vulnerability represents a complete compromise path from web-based content delivery to arbitrary code execution. CISA has confirmed active exploitation and flagged CVE-2013-0074 as associated with ransomware campaigns. With an EPSS percentile of 99.8%, this vulnerability is among the most actively exploited in the entire CVE database. The affected product has reached end of life.

KEV Information

Vendor
Microsoft
Product
Silverlight
Date Added
May 25, 2022
Due Date
June 15, 2022
Required Action
The impacted product is end-of-life and should be disconnected if still in use.

CVSS Score

Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9

Affected Products

VendorProductVersion
microsoftsilverlight>= 5.0, < 5.1.20125.0

Multiple CVSS Assessments

Source: [email protected](Primary)
7.8
HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
7.8
HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References

Weakness Type

Since no specific CWE has been assigned to CVE-2013-0074, the underlying weakness type remains formally unspecified. The vulnerability involves improper pointer validation during HTML object rendering in the Silverlight runtime, which allows an attacker to corrupt memory and redirect execution to attacker-controlled code. This class of weakness typically involves memory corruption through invalid pointer dereference or use-after-free conditions during complex rendering operations.

Impact Analysis

CVE-2013-0074 allows remote attackers to execute arbitrary code on systems running Microsoft Silverlight by delivering a crafted Silverlight application through a web page. The impact is critical: successful exploitation grants the attacker full code execution with the privileges of the user running the browser, enabling file access, malware installation, credential theft, and persistent system compromise. The vulnerability is remotely exploitable with no authentication required, and the only user interaction needed is visiting a web page that loads the malicious Silverlight content. CISA's designation of a known ransomware association confirms that this vulnerability has been directly leveraged in ransomware attack chains. The EPSS percentile of 99.8% places it in the top 0.2% of all CVEs for exploitation likelihood, reflecting its extensive use in exploit kits and targeted attacks during the Silverlight era.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2013-0074 by including it in the Known Exploited Vulnerabilities catalog with a remediation deadline of June 15, 2022. CISA has flagged this vulnerability as associated with ransomware campaigns, indicating it was used in ransomware attack chains. The EPSS percentile of 99.8% makes this one of the most exploited CVEs in the entire database. Microsoft Silverlight code execution vulnerabilities were high-value targets for exploit kit developers due to Silverlight's widespread deployment as a browser plugin, and CVE-2013-0074 was incorporated into multiple exploit frameworks. The end-of-life status of Silverlight means no further patches will be released.

Remediation

  1. Remove Microsoft Silverlight from all systems. CISA's required action states: "The impacted product is end-of-life and should be disconnected if still in use." Since Silverlight has been discontinued, complete removal is the only effective remediation.
  2. Block Silverlight plugin execution in all web browsers through browser settings, group policy, or endpoint management tools to prevent exploitation even if Silverlight remains installed.
  3. Deploy web content filtering at the network level to block web pages known to deliver crafted Silverlight applications targeting this vulnerability.
  4. Scan all systems for remaining Silverlight installations and prioritize their removal, particularly on endpoints that access external web content.
  5. Migrate any remaining applications or workflows that depend on Silverlight to modern web technologies such as HTML5, JavaScript, and WebAssembly, which provide equivalent functionality with active security support.

Technical Details

CVE-2013-0074 exploits a pointer validation flaw in the Microsoft Silverlight runtime that occurs during the rendering of HTML objects. When the Silverlight plugin processes certain crafted HTML element structures, it fails to properly validate pointers used in the rendering pipeline, leading to memory corruption. An attacker can construct a Silverlight application that triggers this improper pointer handling, causing the runtime to dereference an attacker-controlled pointer and redirect code execution to a malicious payload. The attack is delivered through a web page that embeds the crafted Silverlight application, which executes in the context of the Silverlight browser plugin. Successful exploitation results in arbitrary code execution with the privileges of the user running the browser process, which on many systems provides sufficient access for complete system compromise including malware installation and lateral movement.

Frequently Asked Questions

Is CVE-2013-0074 being actively exploited?

Yes, CISA has confirmed active exploitation of CVE-2013-0074 and has flagged it as associated with ransomware campaigns. The EPSS percentile of 99.8% confirms it is among the most exploited CVEs. The vulnerability was widely incorporated into exploit kits targeting Silverlight browser plugins.

What products are affected by CVE-2013-0074?

CVE-2013-0074 affects Microsoft Silverlight. The product has reached end of life and no longer receives security updates. Any system with Silverlight installed is vulnerable, and no patch will be released to address future security issues.

How do I fix CVE-2013-0074?

Since Microsoft Silverlight has reached end of life, the only effective remediation is to completely remove Silverlight from all systems. Block Silverlight plugin execution in browsers and migrate any dependent applications to modern web technologies like HTML5.

How severe is CVE-2013-0074?

CVE-2013-0074 is a critical remote code execution vulnerability with an EPSS percentile of 99.8% and a confirmed association with ransomware campaigns. It allows attackers to execute arbitrary code through crafted Silverlight applications. The end-of-life status of Silverlight means there is no fix, making removal the only effective mitigation.

CVSS Score

7.8
HIGH(7.8)

EPSS Score

EPSS Score81.87%
EPSS Percentile99.6%

Dates

PublishedMarch 13, 2013
Last ModifiedAugust 14, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.