CVE-2016-3391
published 2016-10-14CVE-2016-3391: Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow context-dependent attackers to discover credentials by leveraging access to a memory dump, aka…
PriorityP430medium5.3CVSS 3.0
AVNACHPRNUIRSUCHINAN
EPSS
7.94%
94.1th percentile
Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow context-dependent attackers to discover credentials by leveraging access to a memory dump, aka "Microsoft Browser Information Disclosure Vulnerability."
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| msrc | internet_explorer_10 | — | — |
| msrc | internet_explorer_11 | — | — |
| msrc | internet_explorer_9 | — | — |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
vendor_msrc5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Browser Information Disclosure Vulnerability
vendor_msrc·2016-10-11·CVSS 5.3
CVE-2016-3391 [MEDIUM] Microsoft Browser Information Disclosure Vulnerability
Microsoft Browser Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when affected Microsoft browsers leave credential data in memory. An attacker who successfully exploited this vulnerability could harvest credentials from a memory dump of the browser process. An attacker would need access to a dump of memory from the affected system.
The security update addresses the vulnerability by changing the way that Microsoft browsers store credentials in memory.
Microsoft Browsers: Microsoft Browsers
Impact: Information Disclosure
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely;Older Software Release:Exploitation Unlikely
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=93b4d5dd-
GHSA
GHSA-qcrg-7gwp-23jq: Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow context-dependent attackers to discover credentials by leveraging access to a memory du
ghsa_unreviewed·2022-05-14
CVE-2016-3391 [MEDIUM] CWE-200 GHSA-qcrg-7gwp-23jq: Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow context-dependent attackers to discover credentials by leveraging access to a memory du
Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow context-dependent attackers to discover credentials by leveraging access to a memory dump, aka "Microsoft Browser Information Disclosure Vulnerability."
No detection rules found.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/93379http://www.securitytracker.com/id/1036992http://www.securitytracker.com/id/1036993https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-118https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-119http://www.securityfocus.com/bid/93379http://www.securitytracker.com/id/1036992http://www.securitytracker.com/id/1036993https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-118https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-119
2016-10-14
Published