CVE-2016-3392Medium

Internet Explorer Security Feature Bypass Vulnerability

Published
October 11, 2016
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

A security feature bypass vulnerability exists in Microsoft Internet Explorer where the browser fails to properly restrict mixed content for specifically-crafted documents. An attacker could trick a user into loading a page with malicious content. To exploit the vulnerability, an attacker would need to trick a user into loading a page or visiting a site. The page could also be injected into a compromised site or ad network. The security update corrects how Microsoft Internet Explorer handles mixed content.

🎯 Affected products6

  • Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1511 for 32-bit Systems
  • Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1511 for x64-based Systems
  • Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1607 for 32-bit Systems
  • Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1607 for x64-based Systems
  • Microsoft Edge (EdgeHTML-based) on Windows 10 for 32-bit Systems
  • Microsoft Edge (EdgeHTML-based) on Windows 10 for x64-based Systems

✅ Remediation

KB3192440 (Security Update) KB3192441 (Security Update) KB3194798 (Security Update)

🔗 References (4)