CVE-2016-3325

LOW

Microsoft Edge and Internet Explorer 11 - Information Disclosure via Crafted Web Site

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-3325. PoCs published by Skylined.

AI-analyzed exploit summary This exploit demonstrates an information disclosure vulnerability in WININET.dll (CVE-2016-3325) by crafting a malformed HTTP 100 response to trigger an out-of-bounds read. The PoC uses JavaScript and XMLHttpRequest to exploit the flaw in Microsoft Edge and Internet Explorer.

Description

Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."

Exploits (1)

exploitdb WORKING POC VERIFIED
by Skylined · htmldoswindows
https://www.exploit-db.com/exploits/40747

This exploit demonstrates an information disclosure vulnerability in WININET.dll (CVE-2016-3325) by crafting a malformed HTTP 100 response to trigger an out-of-bounds read. The PoC uses JavaScript and XMLHttpRequest to exploit the flaw in Microsoft Edge and Internet Explorer.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Theoretical
Target: Microsoft WININET.dll (Windows 10, Internet Explorer, Microsoft Edge)
No auth needed
Prerequisites: Victim must visit a malicious webpage or open a crafted media file link · JavaScript must be enabled in the browser
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1036789
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/40747/
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1036788
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/92832

Scores

CVSS v3 3.1
EPSS 0.2431
EPSS Percentile 96.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (2)
microsoft/edge
microsoft/internet_explorer 11
Published Sep 14, 2016
Tracked Since Feb 18, 2026