PT-2016-2902 · Microsoft · Windows 7+4

Published

2016-10-11

·

Updated

2025-04-07

·

CVE-2016-3298

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer versions 9 through 11 Internet Messaging API in Windows Vista SP2 Internet Messaging API in Windows Server 2008 SP2 and R2 SP1 Internet Messaging API in Windows 7 SP1
Description The issue allows remote attackers to determine the existence of arbitrary files via a crafted web site. An attacker who successfully exploited this could test for the presence of files on disk. For an attack to be successful, an attacker must persuade a user to open a malicious website. This is due to Internet Explorer improperly handling objects in memory.
Recommendations For Microsoft Internet Explorer versions 9 through 11, update to a version that properly handles objects in memory to prevent information disclosure. For Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1, restrict access to the API until a patch is available to prevent exploitation. As a temporary workaround, consider restricting user access to malicious websites to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-02333
CVE-2016-3298

Affected Products

Internet Explorer
Windows
Windows 7
Windows Server 2008
Windows Vista