CVE-2016-3392

Description

The Edge Content Security Policy feature in Microsoft Edge does not properly validate documents, which allows remote attackers to bypass intended access restrictions via a crafted web site, aka Microsoft Browser Security Feature Bypass Vulnerability.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
9.43

Associated Vulnerability

VulnerabilityOS Platform
GDI+ Information Disclosure Vulnerability for Windows 10 Version 1511 for x64-based Systems (KB3192441) - CumulativeWindows
GDI+ Information Disclosure Vulnerability for Windows 10 Version 1511 (KB3192441) - CumulativeWindows
GDI+ Information Disclosure Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB3194798) - CumulativeWindows
GDI+ Information Disclosure Vulnerability for Windows 10 Version 1607 (KB3194798) - CumulativeWindows
GDI+ Information Disclosure Vulnerability for Windows 10 for x64-based Systems (KB3192440) - CumulativeWindows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-21535Cumulative Update for Windows 10 Version 1511 for x64-based Systems (KB3192441)
PATCH-21534Cumulative Update for Windows 10 Version 1511 (KB3192441)
PATCH-21537Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB3194798)
PATCH-21536Cumulative Update for Windows 10 Version 1607 (KB3194798)
PATCH-21533Cumulative Update for Windows 10 for x64-based Systems (KB3192440)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234