CVE-2016-3387 EXPLOIT
7.5
HIGH · CVSS 3.0 · EPSS 19.9% (pctl 97)
Patch early
A public exploit exists.
Description
Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remote attackers to gain privileges via unspecified vectors, aka "Microsoft Browser Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3388.
Scoring
| CVSS | 7.5 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 19.93% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2016-10-14 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| microsoft | edge |
| microsoft | internet explorer |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Windows Edge/Internet Explorer - Isolated Private Namespace Insecure Boundary Descriptor Privilege Escalation (MS16-118) | 2016-10-20 |
References
- http://www.securityfocus.com/bid/93381
- http://www.securitytracker.com/id/1036992
- http://www.securitytracker.com/id/1036993
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-118
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-119
- https://www.exploit-db.com/exploits/40607/
- http://www.securityfocus.com/bid/93381
- http://www.securitytracker.com/id/1036992
- http://www.securitytracker.com/id/1036993
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-118
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-119
- https://www.exploit-db.com/exploits/40607/
→ the Explorer · watch your stack · NVD