{"id":"CVE-2016-3351","title":"Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka \"Microsoft Browser Information Disclosure Vulnerability.\"","summary":"Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka \"Microsoft Browser Information Disclosure Vulnerability.\"","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","vendor":"microsoft","product":"internet_explorer","affected":["internet_explorer = 9","internet_explorer = 10","internet_explorer = 11","edge"],"published":"2016-09-14","updated":"2026-08-14","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2016-3351","references":[{"url":"http://www.securityfocus.com/bid/92788","label":"secure@microsoft.com"},{"url":"http://www.securitytracker.com/id/1036788","label":"secure@microsoft.com"},{"url":"http://www.securitytracker.com/id/1036789","label":"secure@microsoft.com"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-104","label":"secure@microsoft.com"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-105","label":"secure@microsoft.com"},{"url":"https://www.brokenbrowser.com/detecting-apps-mimetype-malware/","label":"secure@microsoft.com"},{"url":"http://www.securityfocus.com/bid/92788","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securitytracker.com/id/1036788","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securitytracker.com/id/1036789","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-104","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-105","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.brokenbrowser.com/detecting-apps-mimetype-malware/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-3351","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild"],"epss":0.26286,"epssPercentile":0.97956,"kev":true,"kevDateAdded":"2022-05-24","kevDueDate":"2022-06-14","kevRansomware":true,"exploited":true,"zeroDay":true,"ingestedAt":"2026-08-14T06:15:27.378Z","slug":"CVE-2016-3351","body":"## Overview\n\nMicrosoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka \"Microsoft Browser Information Disclosure Vulnerability.\"\n\n## Affected\n\n- `internet_explorer = 9`\n- `internet_explorer = 10`\n- `internet_explorer = 11`\n- `edge`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":71,"depthScoreParts":{"impact":35.8,"likelihood":5.3,"exploitation":25,"ransomware":5},"changes":[]}