CVE-2016-3388

Published on: 10/13/2016 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:27:03 PM UTC

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N

Certain versions of Edge from Microsoft contain the following vulnerability:

Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remote attackers to gain privileges via unspecified vectors, aka "Microsoft Browser Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3387.

  • CVE-2016-3388 has been assigned by [email protected] to track the vulnerability - currently rated as MEDIUM severity.

CVSS3 Score: 5.3 - MEDIUM

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
NETWORK HIGH NONE REQUIRED
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED NONE HIGH NONE

CVSS2 Score: 2.6 - LOW

Access
Vector
Access
Complexity
Authentication
NETWORK HIGH NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
NONE PARTIAL NONE

CVE References

Description Tags Link
Microsoft Security Bulletin MS16-119 - Critical | Microsoft Docs docs.microsoft.com
text/html
URL Logo MS MS16-119
Microsoft Internet Explorer Multiple Flaws Let Remote Users Obtain Potentially Sensitive Information, Bypass Security, Execute Arbitrary Code, and Gain Elevated Privileges - SecurityTracker www.securitytracker.com
text/html
URL Logo SECTRACK 1036992
Microsoft Security Bulletin MS16-118 - Critical | Microsoft Docs docs.microsoft.com
text/html
URL Logo MS MS16-118
Microsoft Edge Multiple Flaws Let Remote Users Obtain Potentially Sensitive Information, Bypass Security, Execute Arbitrary Code, and Gain Elevated Privileges - SecurityTracker www.securitytracker.com
text/html
URL Logo SECTRACK 1036993
Microsoft Internet Explorer and Edge CVE-2016-3388 Remote Privilege Escalation Vulnerability cve.report (archive)
text/html
URL Logo BID 93382
Microsoft Windows Edge/Internet Explorer - Isolated Private Namespace Insecure DACL Privilege Escalation (MS16-118) - Windows local Exploit www.exploit-db.com
Proof of Concept
text/html
URL Logo EXPLOIT-DB 40606

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationMicrosoftEdgeAllAllAllAll
ApplicationMicrosoftEdgeAllAllAllAll
ApplicationMicrosoftInternet Explorer10AllAllAll
ApplicationMicrosoftInternet Explorer11AllAllAll
ApplicationMicrosoftInternet Explorer10AllAllAll
ApplicationMicrosoftInternet Explorer11AllAllAll
  • cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*:
  • cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*: