CVE-2016-7281
MEDIUMMicrosoft Edge and Internet Explorer - Same Origin Policy Bypass via Web Workers
Title source: llmDescription
The Web Workers implementation in Microsoft Internet Explorer 10 and 11 and Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Browser Security Feature Bypass Vulnerability."
References (4)
Core 4
Core References
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-144
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1037444
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/94723
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-145
Scores
CVSS v3
5.3
EPSS
0.1372
EPSS Percentile
96.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Details
CWE
CWE-254
Status
published
Products (3)
microsoft/edge
microsoft/internet_explorer
10
microsoft/internet_explorer
11
Published
Dec 20, 2016
Tracked Since
Feb 18, 2026