CVE-2016-3298
Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 14 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to determine the existence of arbitrary files via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 32.79% probability · 98th percentile
- CISA KEV
- Listed 24 May 2022 · due 14 June 2022
- Affected
- microsoft/internet explorer · microsoft/windows 7 · microsoft/windows server 2008 · microsoft/windows vista
- Source
- secure@microsoft.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2016-3298
References
- http://www.securityfocus.com/bid/93392Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1036992Broken Link, Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-118Patch, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-126Patch, Vendor Advisory
- http://www.securityfocus.com/bid/93392Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1036992Broken Link, Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-118Patch, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-126Patch, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-3298US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.