🛡 CVE-2016-3351
Microsoft Internet Explorer and Edge Information Disclosure Vulnerability
Microsoft Internet Explorer and Edge CWE-200
Ransomware use
KNOWN
CISA KEV
EPSS
26.3%
Elevated · 98th pct
Added to KEV
2022-05-24
CISA
Remediate by
2022-06-14
⚠ OVERDUE
CWE
CWE-200
weakness
📈 EPSS exploit probability
26.3%
FIRST EPSS — 30-day probability of exploitation in the wild · band Elevated · higher than 98% of all scored CVEs
⚠ KEV remediation overdue
CISA required federal remediation by 2022-06-14. This exploited vulnerability is past its Binding Operational Directive 22-01 due date — prioritize patch/mitigation and hunt for exploitation.
📄 Description
An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific files on the user's computer.
🏹 Attributed exploitation
Malware / ransomware (KEV): ransomware (KEV-flagged)
🔗 External references & OSINT
🔄 Internal pivots & actions
🛡 Add to case
🧩 Advanced Capabilities
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron