CISA Known Exploited Vulnerability

CVE-2016-3298

Microsoft · Internet Explorer

Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability

Date added
BOD 22-01 due date
CWE CWE-200
Ransomware Unknown

CISA description

An information disclosure vulnerability exists when the Microsoft Internet Messaging API improperly handles objects in memory. An attacker who successfully exploited this vulnerability could allow the attacker to test for the presence of files on disk.

Required action

Apply updates per vendor instructions.