CVE-2016-3325 is an information disclosure vulnerability affecting Microsoft Internet Explorer 11 and Microsoft Edge, allowing remote attackers to obtain sensitive information through a crafted website. It has a CVSS v3.0 score of 3.1 (LOW), indicating a network-based attack requiring high attack complexity and user interaction to achieve a low impact on confidentiality. Despite its low CVSS score, its EPSS score is higher than 96% of all CVEs, suggesting a higher-than-average likelihood of exploitation. While there is no evidence of active exploitation in the wild, an ExploitDB entry (EDB-40747) exists for an out-of-bounds read related to WININET.dll, and there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.