CVE-2016-0188Improper Access Control in Microsoft Internet Explorer

Severity
8.8HIGHNVD
EPSS
32.7%
top 3.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 11
Latest updateMay 14

Description

The User Mode Code Integrity (UMCI) implementation in Device Guard in Microsoft Internet Explorer 11 allows remote attackers to bypass a code-signing protection mechanism via unspecified vectors, aka "Internet Explorer Security Feature Bypass."

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-57mm-6wpf-wch6: The User Mode Code Integrity (UMCI) implementation in Device Guard in Microsoft Internet Explorer 11 allows remote attackers to bypass a code-signing2022-05-14
CVEList
CVE-2016-0188: The User Mode Code Integrity (UMCI) implementation in Device Guard in Microsoft Internet Explorer 11 allows remote attackers to bypass a code-signing2016-05-11

📋Vendor Advisories

1
Microsoft
Internet Explorer Security Feature Bypass Vulnerability2016-05-10

🕵️Threat Intelligence

2
Talos
Microsoft Patch Tuesday - May 20162016-05-10
Talos
Microsoft Patch Tuesday - May 20162016-05-10
CVE-2016-0188 — Improper Access Control in Microsoft | cvebase