EXPOSURES › CVE-2016-3351
CVE-2016-3351
CRITICAL ⌖ ON CISA KEV · EXPLOITEDA Microsoft Internet Explorer/Edge vulnerability allowed attackers to detect files on user systems, linked to ransomware activity.
CVE-2016-3351 is an information disclosure vulnerability in Internet Explorer and Edge that enabled attackers to identify files, and has been actively exploited, including in ransomware campaigns. DIB organizations using these browsers face potential data exposure and compliance failures (NIST 800-171 controls 3.1.1, 3.1.2, 3.1.3) and should immediately migrate to supported browsers.
Shame score — The vulnerability's exploitation in ransomware campaigns highlights a significant failure in Microsoft's security practices and a lack of user awareness.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific files on the user's computer.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |