ZeroHour

CVE-2016-0162

KEVmass

Information Disclosure via JavaScript File Detection in Microsoft Internet Explorer

CISA: Microsoft Internet Explorer Information Disclosure Vulnerability

CVSS 3.1
4.3 medium
EPSS
22%p98
Published
()
KEV added
AI analysis

CVE-2016-0162 is an information disclosure flaw (CWE-200) in Microsoft Internet Explorer caused by improper handling of JavaScript, which can allow an attacker to detect the presence of specific files on a user's computer. It is triggered when Internet Explorer processes attacker-controlled JavaScript, typically when a user views a crafted webpage or embedded web content. What the attacker gains is reconnaissance value rather than code execution: confirmation that named files exist on the victim's machine, which can be used to tailor more targeted follow-on attacks. Any user running the affected Internet Explorer versions is potentially exposed, although the source data does not enumerate specific version ranges beyond 'Microsoft Internet Explorer.' The flaw was added to CISA's Known Exploited Vulnerability (KEV) catalog on 2022-05-24, confirming exploitation in the wild; EPSS estimates a 22.1% probability of exploitation within 30 days (98th percentile), and no public proof-of-concept is known.

What to do: Apply Microsoft security updates for Internet Explorer per vendor instructions, prioritizing user workstations and any internet-facing systems where IE is in use, and treat this as a patch-now item given the KEV listing. Verify that IE builds are current against Microsoft's cumulative IE security updates, since the source data does not list specific fixed versions. Where feasible, reduce attack surface by steering users to supported modern browsers or restricting legacy IE to trusted sites; CISA lists ransomware association as unknown, so confirm whether your threat intel ties this CVE to known campaigns.

Affected
Microsoft Internet Explorer
Estimated exposure
masshundreds of millions of users (IE historically shipped by default on Windows; exact counts of unpatched installs unknown) — Internet Explorer was bundled by default with Windows and served hundreds of millions to over a billion users during the affected era, so order-of-magnitude exposure is estimated from IE's ubiquity on Windows rather than any plugin or scan…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka "Internet Explorer Information Disclosure Vulnerability."

CISA Known Exploited Vulnerability
Affected
Microsoft Internet Explorer
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
internet explorer
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

In the news