Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows remote attackers to execute arbitrary code via a crafted Silverlight application, aka "Silverlight Double Dereference Vulnerability."
No PoCs from references.
- https://github.com/Ostorlab/KEV
- https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors
- https://github.com/TwoPt4Mhz/Hun73r
- https://github.com/fkie-cad/nvd-json-data-feeds
- https://github.com/likekabin/CapTipper-original_https-capture
- https://github.com/likescam/CapTipper-original_https-capture
- https://github.com/omriher/CapTipper
- https://github.com/whitfieldsdad/cisa_kev