CVE-2016-3292

MEDIUM

Microsoft Internet Explorer - Improper Input Validation

Title source: rule

Description

Microsoft Internet Explorer 10 and 11 mishandles integrity settings and zone settings, which allows remote attackers to bypass a sandbox protection mechanism via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."

Scores

CVSS v3 5.0
EPSS 0.0643
EPSS Percentile 90.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L

Classification

CWE
CWE-20
Status published

Affected Products (3)

n/a/n/a
microsoft/internet_explorer
microsoft/internet_explorer

Timeline

Published Sep 14, 2016
Tracked Since Feb 18, 2026