CVE-2016-3298: Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability

Published Oct 14, 2016
·
Updated

Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to determine the existence of arbitrary files via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."

Other sources

An information disclosure vulnerability exists when the Microsoft Internet Messaging API improperly handles objects in memory. An attacker who successfully exploited this vulnerability could allow the attacker to test for the presence of files on disk.

CISA

Affected Software

27 affected components
Microsoft Internet Explorer
Microsoft Internet Explorer=9
Microsoft Internet Explorer=10
Microsoft Internet Explorer=11
Microsoft Windows 7=sp1
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=r2-sp1
Microsoft Windows Vista=sp2
All of the following
Microsoft Internet Explorer=9
Any of the following
Microsoft Windows Server 2008=sp2
Microsoft Windows Vista=sp2
All of the following
Microsoft Internet Explorer=10
Microsoft Windows Server 2012
All of the following
Microsoft Internet Explorer=11
Any of the following
Microsoft Windows 10 1507
Microsoft Windows 10 1511
Microsoft Windows 10 1607
Microsoft Windows 7=sp1
Microsoft Windows 8.1
Microsoft Windows RT 8.1
Microsoft Windows Server 2008=r2-sp1
Microsoft Windows Server 2012=r2
Microsoft Windows 7=sp1
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=r2-sp1
Microsoft Windows Server 2008=r2-sp1
Microsoft Windows Vista=sp2

Event History

Oct 14, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·02:59 AM
RemedyDescriptionSeverityAffected Software
May 24, 2022
Known Exploited
via CISA·12:00 AM

Frequently Asked Questions

1

What is the severity of CVE-2016-3298?

The severity of CVE-2016-3298 is classified as critical due to its potential for information disclosure.

2

How do I fix CVE-2016-3298?

To fix CVE-2016-3298, users should apply the latest security updates provided by Microsoft.

3

What versions of Internet Explorer are affected by CVE-2016-3298?

CVE-2016-3298 affects Internet Explorer versions 9, 10, and 11.

4

What operating systems are impacted by CVE-2016-3298?

CVE-2016-3298 impacts Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and their respective server editions.

5

Can CVE-2016-3298 be exploited remotely?

Yes, CVE-2016-3298 can be exploited remotely via a crafted website that allows attackers to determine the existence of arbitrary files.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203