PT-2016-2883 · Microsoft · Edge+1

Published

2016-10-11

·

Updated

2018-10-12

·

CVE-2016-3391

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer versions 10 through 11 Microsoft Edge (affected versions not specified)
Description The issue is related to the lack of protection for sensitive data in Microsoft browsers, allowing a remote attacker to potentially disclose user accounts by analyzing a memory dump. This can enable an attacker to harvest credentials from a memory dump of the browser process.
Recommendations For Microsoft Internet Explorer versions 10 and 11, update to a version that includes the fix for this issue. For Microsoft Edge, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-02314
CVE-2016-3391

Affected Products

Edge
Internet Explorer