Microsoft Silverlight Multiple Vulnerabilities
Last Update Date:
9 Dec 2015 13:55
Release Date:
9 Dec 2015
3848
Views
RISK: Medium Risk
TYPE: Operating Systems - Windows OS
- Microsoft Silverlight RCE Vulnerability
A remote code execution vulnerability exists when Microsoft Silverlight incorrectly handles certain open and close requests that can result in read- and write-access violations. - Multiple Microsoft Silverlight Information Disclosure Vulnerabilities
Multiple information disclosure vulnerabilities exist when Silverlight fails to properly handle objects in memory, which could allow an attacker to more reliably predict pointer values and degrade the efficacy of the Address Space Layout Randomization (ASLR) security feature.
Impact
- Remote Code Execution
- Information Disclosure
System / Technologies affected
- Microsoft Silverlight 5
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
https://technet.microsoft.com/en-us/library/security/MS15-129
Vulnerability Identifier
Source
Related Link
Share with