Junglewise Threat Intelligence

CVE-2016-3298: Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability

CVE-2016-3298 · Severity: critical · CVSS 6.5 · Exploited in the wild · Published 2022-05-24

Technologies: Microsoft Edge, Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

An information disclosure vulnerability exists in Microsoft Internet Explorer and the Windows Internet Messaging API due to improper handling of objects in memory. A remote attacker can exploit this via a crafted website to determine the existence of arbitrary files on the local disk.

Affected products

  • Microsoft Internet Explorer 9 through 11
  • Microsoft Internet Messaging API Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1

Timeline

  • 2016-10-11: patched: Microsoft released security bulletins MS16-118 and MS16-126.
  • 2022-05-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-05-24: disclosed

Related threats