Microsoft Silverlight Double Dereference Vulnerability
Microsoft · Silverlight
Date added (CISA)
2022-05-25
Remediation due
2022-06-15
Known ransomware use
Yes
Remediation priority
P1 — known ransomware use · past CISA due date
Description
Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application.