CVE-2016-3388
MEDIUMMicrosoft Internet Explorer 10-11 and Edge - Elevation of Privilege via Private Namespace Access
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-3388. PoCs published by Google Security Research.
AI-analyzed exploit summary This C++ exploit demonstrates an elevation of privilege (EoP) vulnerability in Windows 10 (10586) and Edge 25.10586.0.0 by exploiting an insecure DACL on an isolated private namespace created by ierutils, allowing any appcontainer process to gain elevated permissions.
Description
Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remote attackers to gain privileges via unspecified vectors, aka "Microsoft Browser Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3387.
Exploits (1)
This C++ exploit demonstrates an elevation of privilege (EoP) vulnerability in Windows 10 (10586) and Edge 25.10586.0.0 by exploiting an insecure DACL on an isolated private namespace created by ierutils, allowing any appcontainer process to gain elevated permissions.
References (6)
Scores
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N