CVE-2016-3351
Description
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
In plain language
AI Act nowCVE-2016-3351 is a browser weakness where a specially made website can trick Internet Explorer or Microsoft Edge into revealing sensitive info; if you or your staff still use these browsers, you should act.
CVE-2016-3351 is a Microsoft Browser Information Disclosure Vulnerability affecting Internet Explorer 9–11 and Microsoft Edge, where a remote attacker can use a crafted website to disclose sensitive information to the browser user; CISA lists it in KEV due to use in ransomware campaigns, so this is a real-world risk.
What to do now
- Check which computers still use Microsoft Internet Explorer 9–11 or Microsoft Edge, and whether those browsers receive Microsoft updates.
- Update the affected browsers to the latest security-patched version available for your Windows setup by following Microsoft’s MS16-104 and MS16-105 remediation guidance.
- If you can’t immediately update, disable or restrict Internet Explorer and block risky browsing paths (so staff cannot reach untrusted or unknown websites).
- Confirm the change by re-checking browser version/build after updates and ensure Windows/Microsoft security updates keep running automatically.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
References
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2016-3351 and every CVE in our database. Create a free account — no credit card required.
Create Free Account