Description
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Microsoft Browser Information Disclosure Vulnerability."
In plain language
AI Low urgencyCVE-2016-7282 is a browser flaw (Internet Explorer 9–11 and Microsoft Edge) that could let an attacker trick the browser into running injected web content; most small businesses don’t need to worry urgently unless you’re using these older browsers.
CVE-2016-7282 is a Cross-site scripting (CWE-79) issue in Microsoft Internet Explorer 9–11 and Microsoft Edge where remote attackers can inject and have the browser execute arbitrary script/HTML through an unspecified vector, with the attack requiring user interaction (a user-triggered navigation).
What to do now
- Check whether any business PCs are still using Microsoft Internet Explorer 9, 10, or 11 or Microsoft Edge in an affected form/version.
- If you do use them, install the vendor remediation from Microsoft security bulletins MS16-144 and MS16-145.
- If you can’t patch right away, reduce exposure by avoiding those browsers for web browsing and switch users to a newer supported browser.
- After updating, confirm normal browser behavior and review browser/app logs for unusual errors while users visit external sites.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:CScopeC:LConfidentialityI:LIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2016-7282 and every CVE in our database. Create a free account — no credit card required.
Create Free Account