Description
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0200 and CVE-2016-3211.
In plain language
AI Worth attentionCVE-2016-0199 is a flaw in Internet Explorer (9–11) that can let someone who tricks you with a specially made website run bad code or crash your browser; a typical small business using IE should treat this as a patch-up-now issue.
CVE-2016-0199 is a memory-corruption issue in Microsoft Internet Explorer 9 through 11 triggered by viewing a crafted website, enabling remote attackers to execute arbitrary code or cause a denial of service.
What to do now
- Check which browser you use on company computers (confirm whether Internet Explorer 9, 10, or 11 is installed and in use for any workflow).
- Apply the vendor fix by installing the update described in Microsoft bulletin MS16-063.
- If you can’t patch immediately, stop using Internet Explorer for web browsing (use an alternative browser) until MS16-063 is installed.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2016-0199 and every CVE in our database. Create a free account — no credit card required.
Create Free Account