CVE-2016-3387
HIGHMicrosoft Internet Explorer 10-11 and Edge - Elevation of Privilege via Private Namespace Access
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-3387. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit demonstrates an elevation of privilege vulnerability in Windows 10 Edge/IE by creating an isolated private namespace with an insecure boundary descriptor. The PoC allows non-appcontainer processes to gain elevated permissions on the namespace directory, potentially leading to privilege escalation.
Description
Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remote attackers to gain privileges via unspecified vectors, aka "Microsoft Browser Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3388.
Exploits (1)
This exploit demonstrates an elevation of privilege vulnerability in Windows 10 Edge/IE by creating an isolated private namespace with an insecure boundary descriptor. The PoC allows non-appcontainer processes to gain elevated permissions on the namespace directory, potentially leading to privilege escalation.
References (6)
Scores
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H