ZeroHour

CVE-2016-3351

KEV ransomware PoC mass

Information Disclosure in Microsoft Internet Explorer and Edge

CISA: Microsoft Internet Explorer and Edge Information Disclosure Vulnerability

CVSS 3.1
6.5 medium
EPSS
26%p98
Published
()
KEV added
AI analysis

CVE-2016-3351 is an information disclosure flaw in the way Internet Explorer and Microsoft Edge handle objects in memory. An attacker can trigger it by getting the browser to process attacker-controlled content, such as a malicious or compromised web page, and thereby determine the presence of specific files on the user's computer. This file-detection capability is useful for profiling a victim machine and is commonly used as a reconnaissance step in broader attack chains. All users of Internet Explorer and Microsoft Edge on affected Microsoft products are impacted; the flaw carries CWE-200 (information exposure) and no CVSS score is available. It was added to the CISA Known Exploited Vulnerabilities catalog on 2022-05-24 with known ransomware use, and EPSS assigns it a 26.3% probability of exploitation within 30 days (98th percentile).

What to do: Apply Microsoft security updates per vendor instructions, as required by the CISA KEV catalog entry, prioritizing internet-facing and user workstations given known ransomware use. Because legacy Internet Explorer is end-of-life, retire or restrict IE usage where possible and confirm that both IE and Edge builds on Windows hosts are fully patched. Hunt for exploitation activity involving browser-based file-detection probes on endpoints in your environment.

Affected
Microsoft Internet Explorer
Microsoft Edge
Estimated exposure
masshundreds of millions of Windows devices (both browsers shipped with Windows) — Internet Explorer and Edge were bundled with essentially every Windows installation at the time of disclosure, so the potential affected population corresponds to the Windows install base, an order of magnitude above 1 million.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."

CISA Known Exploited Vulnerability
Affected
Microsoft Internet Explorer and Edge
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
internet explorer, edge
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news