CVE-2016-3375

Description

The OLE Automation mechanism and VBScript scripting engine in Microsoft Internet Explorer 9 through 11, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka Scripting Engine Memory Corruption Vulnerability.

Risk Information

Base Score
3.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N/E:P/RL:O/RC:C
EPSS Score
Exploitation Probability
26.763

Associated Vulnerability

VulnerabilityOS Platform
Windows Information Disclosure Vulnerability for Windows 10 for x64-based Systems (KB3185611) - CumulativeWindows
Windows Information Disclosure Vulnerability for Windows 10 Version 1511 for x64-based Systems (KB3185614) - CumulativeWindows
Windows Information Disclosure Vulnerability for Windows 10 Version 1511 (KB3185614) - CumulativeWindows
Microsoft Browser Memory Corruption Vulnerability for Internet Explorer 11 for Windows 7 for x64-based Systems (KB3185319) - CumulativeWindows
Microsoft Browser Memory Corruption Vulnerability for Internet Explorer 11 for Windows 7 (KB3185319) - CumulativeWindows
Microsoft Browser Memory Corruption Vulnerability for Internet Explorer 11 for Windows Server 2008 R2 for x64-based Systems (KB3185319) - CumulativeWindows
Microsoft Browser Memory Corruption Vulnerability for Internet Explorer 9 for Windows Server 2008 x64 Edition (KB3185319) - CumulativeWindows
Microsoft Browser Memory Corruption Vulnerability for Internet Explorer 9 for Windows Server 2008 (KB3185319) - CumulativeWindows
Microsoft Browser Memory Corruption Vulnerability for Internet Explorer 9 for Windows Vista for x64-based Systems (KB3185319) - CumulativeWindows
Microsoft Browser Memory Corruption Vulnerability for Internet Explorer 9 for Windows Vista (KB3185319) - CumulativeWindows
Microsoft Browser Memory Corruption Vulnerability for Internet Explorer 10 for Windows Server 2012 (KB3185319) - CumulativeWindows
Microsoft Browser Memory Corruption Vulnerability for Internet Explorer 11 for Windows Server 2012 R2 (KB3185319) - CumulativeWindows
Microsoft Browser Memory Corruption Vulnerability for Internet Explorer 11 for Windows 8.1 for x64-based Systems (KB3185319) - CumulativeWindows
Microsoft Browser Memory Corruption Vulnerability for Internet Explorer 11 for Windows 8.1 (KB3185319) - CumulativeWindows
Scripting Engine Memory Corruption Vulnerability for Windows Server 2008 x64 Edition (KB3184122)Windows
Scripting Engine Memory Corruption Vulnerability for Windows Server 2008 (KB3184122)Windows
Scripting Engine Memory Corruption Vulnerability for Windows Vista for x64-based Systems (KB3184122)Windows
Scripting Engine Memory Corruption Vulnerability for Windows Vista (KB3184122)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 7 for x64-based Systems (KB3184122)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 7 (KB3184122)Windows
Scripting Engine Memory Corruption Vulnerability for Windows Server 2008 R2 x64 Edition (KB3184122)Windows
Scripting Engine Memory Corruption Vulnerability for Windows Server 2012 (KB3184122)Windows
Scripting Engine Memory Corruption Vulnerability for Windows Server 2012 R2 (KB3184122)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 8.1 for x64-based Systems (KB3184122)Windows
Scripting Engine Memory Corruption Vulnerability for Windows 8.1 (KB3184122)Windows
Windows Information Disclosure Vulnerability for Windows 10 (KB3185611)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-21344Cumulative Update for Windows 10 for x64-based Systems (KB3185611)
PATCH-21346Cumulative Update for Windows 10 Version 1511 for x64-based Systems (KB3185614)
PATCH-21345Cumulative Update for Windows 10 Version 1511 (KB3185614)
PATCH-21338Cumulative Security Update for Internet Explorer 11 for Windows 7 for x64-based Systems (KB3185319)
PATCH-21339Cumulative Security Update for Internet Explorer 11 for Windows Server 2008 R2 for x64-based Systems (KB3185319)
PATCH-21333Cumulative Security Update for Internet Explorer 9 for Windows Vista for x64-based Systems (KB3185319)
PATCH-21331Cumulative Security Update for Internet Explorer 9 for Windows Vista (KB3185319)
PATCH-21335Cumulative Security Update for Internet Explorer 10 for Windows Server 2012 (KB3185319)
PATCH-21341Cumulative Security Update for Internet Explorer 11 for Windows Server 2012 R2 (KB3185319)
PATCH-21340Cumulative Security Update for Internet Explorer 11 for Windows 8.1 for x64-based Systems (KB3185319)
PATCH-21337Cumulative Security Update for Internet Explorer 11 for Windows 8.1 (KB3185319)
PATCH-21494Security Update for Windows Server 2008 x64 Edition (KB3184122)
PATCH-21490Security Update for Windows Server 2008 (KB3184122)
PATCH-21493Security Update for Windows Vista for x64-based Systems (KB3184122)
PATCH-21489Security Update for Windows Vista (KB3184122)
PATCH-21495Security Update for Windows 7 for x64-based Systems (KB3184122)
PATCH-21491Security Update for Windows 7 (KB3184122)
PATCH-21496Security Update for Windows Server 2008 R2 x64 Edition (KB3184122)
PATCH-21497Security Update for Windows Server 2012 (KB3184122)
PATCH-21499Security Update for Windows Server 2012 R2 (KB3184122)
PATCH-21498Security Update for Windows 8.1 for x64-based Systems (KB3184122)
PATCH-21492Security Update for Windows 8.1 (KB3184122)
PATCH-21343Cumulative Update for Windows 10 (KB3185611)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234