PT-2016-2902 · Microsoft · Windows 7+4
Publicado
2016-10-11
·
Atualizado
2025-04-07
·
CVE-2016-3298
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer versions 9 through 11
Internet Messaging API in Windows Vista SP2
Internet Messaging API in Windows Server 2008 SP2 and R2 SP1
Internet Messaging API in Windows 7 SP1
Description
The issue allows remote attackers to determine the existence of arbitrary files via a crafted web site. An attacker who successfully exploited this could test for the presence of files on disk. For an attack to be successful, an attacker must persuade a user to open a malicious website. This is due to Internet Explorer improperly handling objects in memory.
Recommendations
For Microsoft Internet Explorer versions 9 through 11, update to a version that properly handles objects in memory to prevent information disclosure.
For Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1, restrict access to the API until a patch is available to prevent exploitation.
As a temporary workaround, consider restricting user access to malicious websites to minimize the risk of exploitation.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Internet Explorer
Windows
Windows 7
Windows Server 2008
Windows Vista