CVE-2016-3292Improper Input Validation in Microsoft Internet Explorer

Severity
5.0MEDIUMNVD
EPSS
6.1%
top 9.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 14
Latest updateMay 14

Description

Microsoft Internet Explorer 10 and 11 mishandles integrity settings and zone settings, which allows remote attackers to bypass a sandbox protection mechanism via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:LExploitability: 1.6 | Impact: 3.4

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-56x2-c3x8-rc2x: Microsoft Internet Explorer 10 and 11 mishandles integrity settings and zone settings, which allows remote attackers to bypass a sandbox protection me2022-05-14
CVEList
CVE-2016-3292: Microsoft Internet Explorer 10 and 11 mishandles integrity settings and zone settings, which allows remote attackers to bypass a sandbox protection me2016-09-14

📋Vendor Advisories

1
Microsoft
Internet Explorer Elevation of Privilege Vulnerability2016-09-13
CVE-2016-3292 — Improper Input Validation in Microsoft | cvebase