Vulnerability identifier: #VU5245
Vulnerability risk: High
CVSSv3.1:
CVE-ID:
CWE-ID:
CWE-119
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
Microsoft Internet Explorer
Client/Desktop applications /
Web browsers
Microsoft Edge
Client/Desktop applications /
Web browsers
Vendor: Microsoft
Description
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The weakness exists due to boundary error when handling of malicious files. A remote attacker can create a specially crafted content, trick the victim into opening it, trigger memory corruption and gain access to arbitrary data.
Mitigation
Install update from vendor's website.
Vulnerable software versions
Microsoft Internet Explorer: 10 - 11
Microsoft Edge:
CPE
External links
http://technet.microsoft.com/en-us/library/security/ms16-104
http://technet.microsoft.com/en-us/library/security/ms16-105
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?