CVE-2016-3374
The PDF library in Microsoft Edge, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted web site, aka "PDF Library Information Disclosure…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 25.8%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The PDF library in Microsoft Edge, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted web site, aka "PDF Library Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3370.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 25.85% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- microsoft/edge · microsoft/windows 10 · microsoft/windows 8.1 · microsoft/windows rt 8.1 · microsoft/windows server 2012
- Source
- secure@microsoft.com
References
- http://blog.malerisch.net/2016/09/microsoft--out-of-bounds-read-pdf-library-cve-2016-3374.html
- http://srcincite.io/advisories/src-2016-39/
- http://www.securityfocus.com/bid/92838
- http://www.securitytracker.com/id/1036789
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-105
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-115
- http://blog.malerisch.net/2016/09/microsoft--out-of-bounds-read-pdf-library-cve-2016-3374.html
- http://srcincite.io/advisories/src-2016-39/
- http://www.securityfocus.com/bid/92838
- http://www.securitytracker.com/id/1036789
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-105
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-115
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.