← Back

CVE-2016-3321

nvd nist
Published: Aug 9, 2016Modified: May 6, 2026

JSON object

Loading...
2.5
Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 1.0 / Impact: 1.4
Source: NVD

Description

Microsoft Internet Explorer 10 and 11 load different files for attempts to open a file:// URL depending on whether the file exists, which allows local users to enumerate files via vectors involving a file:// URL and an HTML5 sandbox iframe, aka "Internet Explorer Information Disclosure Vulnerability."

Affected (2)

1 product
Internet Explorer
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 10
Version 11

References (12)

Source: secure@microsoft.com
Mailing ListThird Party Advisory
Source: secure@microsoft.com
Source: secure@microsoft.com
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.