SB2016071214 - Microsoft Browser Memory Corruption Vulnerability
Published: July 12, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Memory corruption vulnerability (CVE-ID: CVE-2016-3246)
A remote attacker can execute arbitrary code on the target system.
The vulnerability resides within InjectHtmlStream. A remote attacker can create manipulate document elements and read portions of memory or cause memory corruption.
Successful exploitation may allow a remote attacker to execute arbitrary code on the target system with privileges of current user.
Remediation
Install update from vendor's website.