First published: Thu Nov 10 2016(Updated: )
The RegEx class in the XSS filter in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allows remote attackers to conduct cross-site scripting (XSS) attacks and obtain sensitive information via unspecified vectors, aka "Microsoft Browser Information Disclosure Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Edge Beta | ||
Internet Explorer | =9 | |
Internet Explorer | =10 | |
Internet Explorer | =11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7239 has a severity rating of important, indicating a significant risk of exploitation.
To fix CVE-2016-7239, users should apply the security updates provided by Microsoft for Internet Explorer and Edge.
CVE-2016-7239 allows attackers to conduct cross-site scripting (XSS) attacks.
CVE-2016-7239 affects Microsoft Internet Explorer versions 9, 10, and 11, as well as Microsoft Edge.
Exploitation of CVE-2016-7239 could allow attackers to obtain sensitive information from users.