logo

Exploit Kits: Anatomy Of A Silverlight Exploit

ID: ea540e70-cf83-50c8-97bd-a3c86412d5a3

STIX ID: report--ea540e70-cf83-50c8-97bd-a3c86412d5a3

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report analyzes how popular exploit kits (e.g., Nuclear, Fiesta) weaponize Silverlight vulnerabilities—CVE-2013-0074 (arbitrary code execution) and CVE-2013-3896 (memory disclosure)—via malicious XAP payloads. It describes the exploit chain and DLL reverse-engineering findings, shows how the payloads calculate base addresses and trigger vulnerabilities to execute shellcode, and provides a list of recently observed Nuclear EK domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.