CVE-2016-0199

Published on: 06/15/2016 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:27:14 PM UTC

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Certain versions of Internet Explorer from Microsoft contain the following vulnerability:

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0200 and CVE-2016-3211.

  • CVE-2016-0199 has been assigned by URL Logo [email protected] to track the vulnerability - currently rated as HIGH severity.

CVSS3 Score: 8.8 - HIGH

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
NETWORK LOW NONE REQUIRED
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED HIGH HIGH HIGH

CVSS2 Score: 9.3 - HIGH

Access
Vector
Access
Complexity
Authentication
NETWORK MEDIUM NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
COMPLETE COMPLETE COMPLETE

CVE References

Description Tags Link
SecurityFocus www.securityfocus.com
text/html
URL Logo BUGTRAQ 20160617 CVE-2016-0199 / MS16-063: MSIE 11 garbage collector attribute type confusion
Microsoft Security Bulletin MS16-063 - Critical | Microsoft Docs docs.microsoft.com
text/html
URL Logo MS MS16-063
Full Disclosure: CVE-2016-0199 / MS16-063: MSIE 11 garbage collector attribute type confusion Mailing List
Third Party Advisory
seclists.org
text/html
URL Logo FULLDISC 20160618 CVE-2016-0199 / MS16-063: MSIE 11 garbage collector attribute type confusion
Microsoft Internet Explorer 11 - Garbage Collector Attribute Type Confusion (MS16-063) - Windows dos Exploit Exploit
Third Party Advisory
VDB Entry
www.exploit-db.com
Proof of Concept
text/html
URL Logo EXPLOIT-DB 39994
Verisign is a global provider of domain name registry services and internet infrastructure - Verisign Third Party Advisory
VDB Entry
www.verisign.com
text/xml
URL Logo IDEFENSE 20160614 Microsoft Internet Explorer 11 Garbage Collector Attribute Type Confusion Vulnerability
Microsoft Internet Explorer Multiple Flaws Let Remote Users Execute Arbitrary Code, Gain Elevated Privileges, and Conduct Cross-Site Scripting Attacks - SecurityTracker Third Party Advisory
VDB Entry
www.securitytracker.com
text/html
URL Logo SECTRACK 1036096
Microsoft Internet Explorer 11 Garbage Collector Attribute Type Confusion ≈ Packet Storm Exploit
Third Party Advisory
VDB Entry
packetstormsecurity.com
text/html
URL Logo MISC packetstormsecurity.com/files/137533/Microsoft-Internet-Explorer-11-Garbage-Collector-Attribute-Type-Confusion.html

Exploit/POC from Github

Proof-of-Concept CVE-2016-0199

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationMicrosoftInternet Explorer10AllAllAll
ApplicationMicrosoftInternet Explorer11-AllAll
ApplicationMicrosoftInternet Explorer9AllAllAll
ApplicationMicrosoftInternet Explorer10AllAllAll
ApplicationMicrosoftInternet Explorer11-AllAll
ApplicationMicrosoftInternet Explorer9AllAllAll
  • cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*: