Vulnerability Name: | CVE-2016-3388 (CCN-117264) | ||||||||||||
Assigned: | 2016-10-11 | ||||||||||||
Published: | 2016-10-11 | ||||||||||||
Updated: | 2018-10-12 | ||||||||||||
Summary: | Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remote attackers to gain privileges via unspecified vectors, aka "Microsoft Browser Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3387. | ||||||||||||
CVSS v3 Severity: | 5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N) 4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N/E:P/RL:O/RC:C)
4.0 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:P/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N)
| ||||||||||||
Vulnerability Type: | CWE-264 | ||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-3388 Source: CCN Type: Microsoft Security Bulletin MS16-118 Cumulative Security Update for Internet Explorer (3192887) Source: CCN Type: Microsoft Security Bulletin MS16-119 Cumulative Security Update for Microsoft Edge (3192890) Source: CCN Type: Microsoft Security Bulletin MS16-129 Cumulative Security Update for Microsoft Edge (3199057) Source: CCN Type: Microsoft Security Bulletin MS16-142 Cumulative Security Update for Internet Explorer (3198467) Source: CCN Type: Microsoft Security Bulletin MS16-144 Cumulative Security Update for Internet Explorer (3204059) Source: CCN Type: Microsoft Security Bulletin MS16-145 Cumulative Security Update for Microsoft Edge (3204062) Source: CCN Type: Microsoft Security Bulletin MS17-001 Cumulative Security Update for Microsoft Edge (3214288) Source: CCN Type: Microsoft Security Bulletin MS17-006 Cumulative Security Update for Internet Explorer (4013073) Source: CCN Type: Microsoft Security Bulletin MS17-007 Security Update for Microsoft Edge (4013071) Source: BID Type: UNKNOWN 93382 Source: SECTRACK Type: UNKNOWN 1036992 Source: SECTRACK Type: UNKNOWN 1036993 Source: MS Type: UNKNOWN MS16-118 Source: MS Type: UNKNOWN MS16-119 Source: XF Type: UNKNOWN ms-browsers-cve20163388-priv-esc(117264) Source: CCN Type: Packet Storm Security [10-19-2016] Windows Edge/IE Isolated Private Namespace Insecure DACL Privilege Escalation Source: EXPLOIT-DB Type: UNKNOWN 40606 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |