Information disclosure in Microsoft Edge and Microsoft Internet Explorer - CVE-2016-3391
Published: October 12, 2016 / Updated: February 14, 2017
Vulnerability identifier: #VU849
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-3391
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The weakness exists due to improper storage of credential data in memory. A remote attacker can access access a memory dump and get credential information.
Successful exploitation of the vulnerability will result in personal data disclosure.
The weakness exists due to improper storage of credential data in memory. A remote attacker can access access a memory dump and get credential information.
Successful exploitation of the vulnerability will result in personal data disclosure.
Affected software
Microsoft Edge
Microsoft Internet Explorer
Microsoft Internet Explorer
How to mitigate CVE-2016-3391
Install update from vendor's website.