Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2016-7199

Опубликовано: 08 нояб. 2016
Источник: msrc
CVSS3: 4.3
EPSS Средний

Описание

Microsoft Browser Information Disclosure Vulnerability

An information disclosure vulnerability exists when affected Microsoft browsers improperly allow cross-frame interaction. An attacker who successfully exploited this vulnerability could allow an attacker to obtain browser frame or window state from a different domain.

For an attack to be successful, an attacker must persuade a user to open a malicious website from a secure website.

This update addresses the vulnerability by denying permission to read the state of the object model, to which frames or windows on different domains should not have access.

Обновления

ПродуктСтатьяОбновление
Microsoft Edge (EdgeHTML-based) on Windows 10 for 32-bit Systems
Microsoft Edge (EdgeHTML-based) on Windows 10 for x64-based Systems
Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1511 for 32-bit Systems
Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1511 for x64-based Systems
Microsoft Edge (EdgeHTML-based) on Windows Server 2016
Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1607 for 32-bit Systems
Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1607 for x64-based Systems
Internet Explorer 10 on Windows Server 2012
Internet Explorer 11 on Windows 8.1 for 32-bit systems
Internet Explorer 11 on Windows 8.1 for x64-based systems

Показывать по

Возможность эксплуатации

Publicly Disclosed

Yes

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

N/A

EPSS

Процентиль: 95%
0.16588
Средний

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.1
nvd
больше 8 лет назад

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to bypass the Same Origin Policy and obtain sensitive window-state information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."

CVSS3: 3.1
github
около 3 лет назад

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to bypass the Same Origin Policy and obtain sensitive window-state information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."

fstec
больше 8 лет назад

Уязвимость браузеров Internet Exlorer и Microsoft Edge, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код

EPSS

Процентиль: 95%
0.16588
Средний

4.3 Medium

CVSS3