CVE-2016-0162
KEVmassInformation Disclosure via JavaScript File Detection in Microsoft Internet Explorer
CISA: Microsoft Internet Explorer Information Disclosure Vulnerability
CVE-2016-0162 is an information disclosure flaw (CWE-200) in Microsoft Internet Explorer caused by improper handling of JavaScript, which can allow an attacker to detect the presence of specific files on a user's computer. It is triggered when Internet Explorer processes attacker-controlled JavaScript, typically when a user views a crafted webpage or embedded web content. What the attacker gains is reconnaissance value rather than code execution: confirmation that named files exist on the victim's machine, which can be used to tailor more targeted follow-on attacks. Any user running the affected Internet Explorer versions is potentially exposed, although the source data does not enumerate specific version ranges beyond 'Microsoft Internet Explorer.' The flaw was added to CISA's Known Exploited Vulnerability (KEV) catalog on 2022-05-24, confirming exploitation in the wild; EPSS estimates a 22.1% probability of exploitation within 30 days (98th percentile), and no public proof-of-concept is known.
What to do: Apply Microsoft security updates for Internet Explorer per vendor instructions, prioritizing user workstations and any internet-facing systems where IE is in use, and treat this as a patch-now item given the KEV listing. Verify that IE builds are current against Microsoft's cumulative IE security updates, since the source data does not list specific fixed versions. Where feasible, reduce attack surface by steering users to supported modern browsers or restricting legacy IE to trusted sites; CISA lists ransomware association as unknown, so confirm whether your threat intel ties this CVE to known campaigns.
| Microsoft Internet Explorer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka "Internet Explorer Information Disclosure Vulnerability."
- Affected
- Microsoft Internet Explorer
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- internet explorer
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N