6.5

CVE-2016-3298

Warnung
Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to determine the existence of arbitrary files via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Explorer Version 9
   Microsoft ≫ Windows Server 2008 Version - Update sp2
   Microsoft ≫ Windows Vista Version - Update sp2
Microsoft ≫ Internet Explorer Version 10
   Microsoft ≫ Windows Server 2012 Version -
Microsoft ≫ Internet Explorer Version 11 Update -
   Microsoft ≫ Windows 10 1507 Version -
   Microsoft ≫ Windows 10 1511 Version -
   Microsoft ≫ Windows 10 1607 Version -
   Microsoft ≫ Windows 7 Version - Update sp1
   Microsoft ≫ Windows 8.1 Version -
   Microsoft ≫ Windows Rt 8.1 Version -
   Microsoft ≫ Windows Server 2008 Version r2 Update sp1 HwPlatform x64
   Microsoft ≫ Windows Server 2012 Version r2
Microsoft ≫ Windows 7 Version - Update sp1
Microsoft ≫ Windows Server 2008 Version - Update sp2
Microsoft ≫ Windows Server 2008 Version r2 Update sp1 HwPlatform itanium
Microsoft ≫ Windows Server 2008 Version r2 Update sp1 HwPlatform x64
Microsoft ≫ Windows Vista Version - Update sp2

24.05.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability

Schwachstelle

An information disclosure vulnerability exists when the Microsoft Internet Messaging API improperly handles objects in memory. An attacker who successfully exploited this vulnerability could allow the attacker to test for the presence of files on disk.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 23.48% 0.976
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
NIST 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:P/I:N/A:N
CISA-ADP 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.securitytracker.com/id/1036992
Third Party Advisory
Broken Link
VDB Entry
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-118
Patch
Vendor Advisory
http://www.securityfocus.com/bid/93392
Third Party Advisory
Broken Link
VDB Entry
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-126
Patch
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-3298
US Government Resource