peter bassill · operator
$ cve CVE-2016-3387 JSON

CVE-2016-3387 EXPLOIT

7.5
HIGH · CVSS 3.0 · EPSS 19.9% (pctl 97)

Patch early

A public exploit exists.

Description

Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remote attackers to gain privileges via unspecified vectors, aka "Microsoft Browser Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3388.

Scoring

CVSS7.5 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS19.93% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2016-10-14
Last modified2026-06-17

Affected (2)

VendorProduct
microsoftedge
microsoftinternet explorer

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD