4.3
CVE-2016-0162
- EPSS 22.09%
- Veröffentlicht 12.04.2016 23:59:26
- Zuletzt bearbeitet 21.04.2026 19:04:50
- Erkennungen
Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka "Internet Explorer Information Disclosure Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Explorer Version 9
Microsoft ≫ Internet Explorer Version 10
Microsoft ≫ Internet Explorer Version 11 Update -
Microsoft ≫ Windows 10 1507 Version -
Microsoft ≫ Windows 10 1511 Version -
Microsoft ≫ Windows 7 Version - Update sp1
Microsoft ≫ Windows 8.1 Version -
Microsoft ≫ Windows Rt 8.1 Version -
Microsoft ≫ Windows Server 2008 Version r2 Update sp1
Microsoft ≫ Windows Server 2012 Version r2
Microsoft ≫ Windows 10 1511 Version -
Microsoft ≫ Windows 7 Version - Update sp1
Microsoft ≫ Windows 8.1 Version -
Microsoft ≫ Windows Rt 8.1 Version -
Microsoft ≫ Windows Server 2008 Version r2 Update sp1
Microsoft ≫ Windows Server 2012 Version r2
24.05.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
Microsoft Internet Explorer Information Disclosure Vulnerability
SchwachstelleAn information disclosure vulnerability exists when Internet Explorer does not properly handle JavaScript. The vulnerability could allow an attacker to detect specific files on the user's computer.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 22.09% | 0.974 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
| CISA-ADP | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
|
http://www.securitytracker.com/id/1035521
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-037
http://www.securityfocus.com/bid/85939
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-0162