Umbra Wiki cve cve/CVE-2016-3298
Back to wiki

CVE-2016-3298 — Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability

provenance: imported · CVE: CVE-2016-3298

CVE-2016-3298: Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Microsoft
Product Internet Explorer
Date added 2022-05-24
Due date 2022-06-14
Ransomware campaign use Unknown

Description

An information disclosure vulnerability exists when the Microsoft Internet Messaging API improperly handles objects in memory. An attacker who successfully exploited this vulnerability could allow the attacker to test for the presence of files on disk.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2016-3298

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2016-3298
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog