Microsoft Internet Explorer and Edge Information Disclosure Vulnerability
Medium CVSS 6.5 Listed in CISA KEV
Summary
An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific files on the user's computer.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- Microsoft:Internet Explorer and Edge
- :
- :
- :
- :
Sources
- CISA KEV DATABASE
- NVD DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2016-3351 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- http://www.securityfocus.com/bid/92788 Broken Link
- http://www.securitytracker.com/id/1036788 Broken Link
- http://www.securitytracker.com/id/1036789 Broken Link
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-104 Patch
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-105 Patch
- https://www.brokenbrowser.com/detecting-apps-mimetype-malware/ Exploit
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-3351 US Government Resource
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV
- nvd_ingest NVD