PT-2016-1165 · Microsoft · Internet Explorer

Published

2016-02-09

·

Updated

2018-10-12

·

CVE-2016-0059

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer versions 9 through 11
Description The issue is related to the Hyperlink Object Library in Microsoft Internet Explorer, which allows remote attackers to obtain sensitive information from process memory via a crafted URL in an e-mail message or Office document. An attacker who successfully exploits this issue could obtain information to further compromise the user's system. To exploit the issue, an attacker must convince a user to either click a link in an email message or open an Office file, and then click a link in the file.
Recommendations For Microsoft Internet Explorer versions 9 through 11, there is no information about a newer version that contains a fix for this issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00426
CVE-2016-0059

Affected Products

Internet Explorer