Junglewise Threat Intelligence

CVE-2016-0162: Microsoft Internet Explorer Information Disclosure Vulnerability

CVE-2016-0162 · Severity: critical · CVSS 4.3 · Exploited in the wild · Published 2022-05-24

Technologies: Microsoft Edge, Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

An information disclosure vulnerability in Microsoft Internet Explorer 9 through 11 occurs when JavaScript is not properly handled. A remote attacker can exploit this by using crafted JavaScript code to detect the existence of specific files on a user's computer.

Affected products

  • Microsoft Internet Explorer 9 through 11

Timeline

  • 2016-04-12: advisory: Initial Microsoft security bulletin MS16-037 published.
  • 2022-05-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-05-24: disclosed: NVD publication date.

Related threats