PT-2016-2897 · Microsoft · Windows Server 2012+5

Publicado

2016-09-13

·

Atualizado

2018-10-12

·

CVE-2016-3370

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Edge versions prior to the fixed version Windows versions prior to the fixed version, including Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607
Description The issue allows an attacker to obtain sensitive information. This is achieved through a crafted web site that exploits the PDF library in Microsoft Edge and certain Windows operating systems.
Recommendations For Microsoft Edge, update to a version that includes the fix for this issue. For Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the PDF library in Microsoft Edge until a patch is available.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-02328
CVE-2016-3370

Produtos afetados

Edge
Windows
Windows 10
Windows 8.1
Windows Rt 8.1
Windows Server 2012