CVE-2016-3325
LOWMicrosoft Edge and Internet Explorer 11 - Information Disclosure via Crafted Web Site
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-3325. PoCs published by Skylined.
AI-analyzed exploit summary This exploit demonstrates an information disclosure vulnerability in WININET.dll (CVE-2016-3325) by crafting a malformed HTTP 100 response to trigger an out-of-bounds read. The PoC uses JavaScript and XMLHttpRequest to exploit the flaw in Microsoft Edge and Internet Explorer.
Description
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
Exploits (1)
This exploit demonstrates an information disclosure vulnerability in WININET.dll (CVE-2016-3325) by crafting a malformed HTTP 100 response to trigger an out-of-bounds read. The PoC uses JavaScript and XMLHttpRequest to exploit the flaw in Microsoft Edge and Internet Explorer.
References (6)
Scores
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N