CVE-2016-3351: Microsoft Internet Explorer and Edge Information Disclosure Vulnerability
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
Other sources
An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific files on the user's computer.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3351?
CVE-2016-3351 is classified as a medium severity information disclosure vulnerability.
How do I fix CVE-2016-3351?
To mitigate CVE-2016-3351, ensure that your version of Internet Explorer or Microsoft Edge is updated to the latest version.
Which versions of Internet Explorer are affected by CVE-2016-3351?
CVE-2016-3351 affects Microsoft Internet Explorer versions 9, 10, and 11.
Which versions of Microsoft Edge are impacted by CVE-2016-3351?
CVE-2016-3351 impacts all versions of Microsoft Edge.
Can CVE-2016-3351 lead to unauthorized data exposure?
Yes, CVE-2016-3351 may allow attackers to obtain sensitive information through a crafted website.