Junglewise Threat Intelligence

CVE-2016-3351: Microsoft Internet Explorer and Edge Information Disclosure Vulnerability

CVE-2016-3351 · Severity: critical · CVSS 6.5 · Exploited in the wild · Published 2022-05-24

Technologies: Microsoft Edge, Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

An information disclosure vulnerability in Microsoft Internet Explorer and Edge occurs when certain functions handle objects in memory. A remote attacker can exploit this via a crafted website to detect specific files on a user's computer or obtain other sensitive information.

Affected products

  • Microsoft Internet Explorer 9 through 11
  • Microsoft Edge

Timeline

  • 2016-09-13: patched: Microsoft released security bulletins MS16-104 and MS16-105.
  • 2022-05-24: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
  • 2022-05-24: disclosed: NVD publication date.

Related threats