PT-2016-2902 · Microsoft · Windows 7+4
Published
2016-10-11
·
Updated
2025-04-07
·
CVE-2016-3298
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer versions 9 through 11
Internet Messaging API in Windows Vista SP2
Internet Messaging API in Windows Server 2008 SP2 and R2 SP1
Internet Messaging API in Windows 7 SP1
Description
The issue allows remote attackers to determine the existence of arbitrary files via a crafted web site. An attacker who successfully exploited this could test for the presence of files on disk. For an attack to be successful, an attacker must persuade a user to open a malicious website. This is due to Internet Explorer improperly handling objects in memory.
Recommendations
For Microsoft Internet Explorer versions 9 through 11, update to a version that properly handles objects in memory to prevent information disclosure.
For Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1, restrict access to the API until a patch is available to prevent exploitation.
As a temporary workaround, consider restricting user access to malicious websites to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Explorer
Windows
Windows 7
Windows Server 2008
Windows Vista