6.5

CVE-2016-3351

Warnung
Exploit
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Explorer Version 9
   Microsoft ≫ Windows Server 2008 Version - Update sp2
   Microsoft ≫ Windows Vista Version - Update sp2
Microsoft ≫ Internet Explorer Version 10
   Microsoft ≫ Windows Server 2012 Version -
Microsoft ≫ Internet Explorer Version 11 Update -
   Microsoft ≫ Windows 10 1507 Version -
   Microsoft ≫ Windows 10 1511 Version -
   Microsoft ≫ Windows 10 1607 Version -
   Microsoft ≫ Windows 7 Version - Update sp1
   Microsoft ≫ Windows 8.1 Version -
   Microsoft ≫ Windows Rt 8.1 Version -
   Microsoft ≫ Windows Server 2008 Version r2 Update sp1 HwPlatform x64
   Microsoft ≫ Windows Server 2012 Version r2
Microsoft ≫ Edge Version -
   Microsoft ≫ Windows 10 1507 Version -
   Microsoft ≫ Windows 10 1511 Version -
   Microsoft ≫ Windows 10 1607 Version -

24.05.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Microsoft Internet Explorer and Edge Information Disclosure Vulnerability

Schwachstelle

An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific files on the user's computer.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 26.29% 0.977
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
NIST 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:P/I:N/A:N
CISA-ADP 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.securitytracker.com/id/1036788
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id/1036789
Third Party Advisory
Broken Link
VDB Entry
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-104
Patch
Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-105
Patch
Vendor Advisory
http://www.securityfocus.com/bid/92788
Third Party Advisory
Broken Link
VDB Entry
https://www.brokenbrowser.com/detecting-apps-mimetype-malware/
Exploit
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-3351
US Government Resource