← KEV catalog
CISA known exploited vulnerability

CVE-2016-3298

Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability

SOURCE FACT

Microsoft · Internet Explorer

An information disclosure vulnerability exists when the Microsoft Internet Messaging API improperly handles objects in memory. An attacker who successfully exploited this vulnerability could allow the attacker to test for the presence of files on disk.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2016-3298

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?