Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2016-3245

Опубликовано: 12 июл. 2016
Источник: msrc
CVSS3: 3.5
EPSS Средний

Описание

Internet Explorer Security Feature Bypass Vulnerability

A restricted ports security feature bypass vulnerability exists for Internet Explorer. An attacker could take advantage of the vulnerability to trick a user into connecting to a remote system.

To exploit the vulnerability, an attacker would have to either convince a user to visit a malicious website or inject malicious code into a compromised website.

The update addresses the vulnerability by correcting how Internet Explorer validates URLs for restricted ports.

Обновления

ПродуктСтатьяОбновление
Internet Explorer 9 on Windows Server 2008 for 32-bit Systems Service Pack 2
Internet Explorer 9 on Windows Server 2008 for x64-based Systems Service Pack 2
Internet Explorer 9 on Windows Vista Service Pack 2
Internet Explorer 9 on Windows Vista x64 Edition Service Pack 2
Internet Explorer 11 on Windows 7 for 32-bit Systems Service Pack 1
Internet Explorer 11 on Windows 7 for x64-based Systems Service Pack 1
Internet Explorer 11 on Windows Server 2008 R2 for x64-based Systems Service Pack 1
Internet Explorer 10 on Windows Server 2012
Internet Explorer 11 on Windows 8.1 for 32-bit systems
Internet Explorer 11 on Windows 8.1 for x64-based systems

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Unlikely

Older Software Release

Exploitation Unlikely

EPSS

Процентиль: 93%
0.11962
Средний

3.5 Low

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
почти 9 лет назад

Microsoft Internet Explorer 9 through 11 allows remote attackers to trick users into making TCP connections to a restricted port via a crafted web site, aka "Internet Explorer Security Feature Bypass Vulnerability."

CVSS3: 6.5
github
около 3 лет назад

Microsoft Internet Explorer 9 through 11 allows remote attackers to trick users into making TCP connections to a restricted port via a crafted web site, aka "Internet Explorer Security Feature Bypass Vulnerability."

fstec
почти 9 лет назад

Уязвимость браузера Internet Explorer, позволяющая нарушителю обманным путем заставить пользователей создать TCP-соединение с ограниченным портом

EPSS

Процентиль: 93%
0.11962
Средний

3.5 Low

CVSS3