Description
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code via a crafted web page, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3290.
In plain language
AI Worth attentionCVE-2016-3288 is a bug in Internet Explorer 11 that can let a malicious website crash the browser or run unauthorized code when someone visits the page; most small businesses should treat this as a real patching priority if any staff still use IE11.
CVE-2016-3288 is a memory-handling flaw in Microsoft Internet Explorer 11 that allows remote attackers to execute arbitrary code with the privileges of the logged-in user via a crafted web page; it requires user interaction (the victim must visit the malicious page) and does not require any login to the target.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2016-3288 and every CVE in our database. Create a free account — no credit card required.
Create Free Account