Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2016-3374

Опубликовано: 13 сент. 2016
Источник: msrc
CVSS3: 3.1
EPSS Средний

Описание

Microsoft Browser Information Disclosure Vulnerability

An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.

To exploit the vulnerability, in a web-based attack scenario, an attacker could host a website that is used to attempt to exploit the vulnerability. In addition, compromised websites and websites that accept or host user-provided content could contain specially crafted content that could exploit the vulnerability. However, in all cases an attacker would have no way to force a user to view the attacker-controlled content. Instead, an attacker would have to convince a user to take action. For example, an attacker could trick a user into clicking a link that takes the user to the attacker's site.

The security update addresses the vulnerability by modifying how Microsoft browsers handle objects in memory.

FAQ

The security updates Windows 10 appear twice in the Affected Products table. To be protected from this vulnerability, do I need to install multiple updates for my particular system? No. Customers running Windows 10 systems only need to install the one cumulative update for their system to be protected from this vulnerability. The security updates are also listed for systems with Windows 10 and Microsoft Edge configurations because on Windows 10 systems, the security fixes for these vulnerabilities reside in the Microsoft Edge component that is shipping in the cumulative update.

Обновления

ПродуктСтатьяОбновление
Windows Server 2012
Windows 8.1 for 32-bit systems
Windows 8.1 for x64-based systems
Windows Server 2012 R2
Windows RT 8.1
-
Windows 10 for 32-bit Systems
Windows 10 for x64-based Systems
Windows 10 Version 1511 for x64-based Systems
Windows 10 Version 1511 for 32-bit Systems
Windows 10 Version 1607 for 32-bit Systems

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation More Likely

Older Software Release

N/A

DOS

N/A

EPSS

Процентиль: 97%
0.34166
Средний

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
почти 9 лет назад

The PDF library in Microsoft Edge, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted web site, aka "PDF Library Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3370.

CVSS3: 6.5
github
около 3 лет назад

The PDF library in Microsoft Edge, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted web site, aka "PDF Library Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3370.

fstec
почти 9 лет назад

Уязвимость браузера Microsoft Edge и операционной системы Windows, позволяющая нарушителю получить конфиденциальную информацию

EPSS

Процентиль: 97%
0.34166
Средний

3.1 Low

CVSS3