← Back

CVE-2016-3298

nvd nist
Published: Oct 14, 2016Modified: Apr 22, 2026CISA KEV

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to determine the existence of arbitrary files via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."

Affected (8)

4 products
Internet Explorer
Windows 7
Windows Server 2008
Windows Vista
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 9
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 10
Running on/withPlatform Versions
Microsoft
Windows Server 2012
All versions
Configuration C
1 vulnerable · 6 platform
Vulnerable SoftwareAffected Versions
Version 11
Running on/withPlatform Versions
Microsoft
Windows 10 1507
All versions
Microsoft
Windows 10 1511
All versions
Microsoft
Windows 10 1607
All versions
Microsoft
Windows 8.1
All versions
Microsoft
Windows Rt 8.1
All versions
Microsoft
Windows Server 2012
Version r2
Configuration D
5 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Microsoft
All versions
Version r2 sp1
Version r2 sp1
All versions

References (9)

Source: secure@microsoft.com
Broken LinkThird Party AdvisoryVDB Entry
Source: secure@microsoft.com
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.