First published: Thu Nov 10 2016(Updated: )
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to bypass the Same Origin Policy and obtain sensitive window-state information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Edge Beta | ||
Internet Explorer | =9 | |
Internet Explorer | =10 | |
Internet Explorer | =11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7199 is classified as a critical information disclosure vulnerability.
To mitigate CVE-2016-7199, users should update their Microsoft Internet Explorer or Edge to the latest security patches provided by Microsoft.
CVE-2016-7199 affects users of Microsoft Internet Explorer versions 9, 10, and 11, as well as Microsoft Edge.
CVE-2016-7199 is associated with remote attacks that exploit the Same Origin Policy to disclose sensitive information.
By exploiting CVE-2016-7199, attackers can obtain sensitive window-state information from affected web browsers.