CVE-2016-3351
KEV ransomware PoC massInformation Disclosure in Microsoft Internet Explorer and Edge
CISA: Microsoft Internet Explorer and Edge Information Disclosure Vulnerability
CVE-2016-3351 is an information disclosure flaw in the way Internet Explorer and Microsoft Edge handle objects in memory. An attacker can trigger it by getting the browser to process attacker-controlled content, such as a malicious or compromised web page, and thereby determine the presence of specific files on the user's computer. This file-detection capability is useful for profiling a victim machine and is commonly used as a reconnaissance step in broader attack chains. All users of Internet Explorer and Microsoft Edge on affected Microsoft products are impacted; the flaw carries CWE-200 (information exposure) and no CVSS score is available. It was added to the CISA Known Exploited Vulnerabilities catalog on 2022-05-24 with known ransomware use, and EPSS assigns it a 26.3% probability of exploitation within 30 days (98th percentile).
What to do: Apply Microsoft security updates per vendor instructions, as required by the CISA KEV catalog entry, prioritizing internet-facing and user workstations given known ransomware use. Because legacy Internet Explorer is end-of-life, retire or restrict IE usage where possible and confirm that both IE and Edge builds on Windows hosts are fully patched. Hunt for exploitation activity involving browser-based file-detection probes on endpoints in your environment.
| Microsoft Internet Explorer | — |
| Microsoft Edge | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
- Affected
- Microsoft Internet Explorer and Edge
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- internet explorer, edge
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N