CVE-2016-3353

Severity CVSS v4.0:
Pending analysis
Type:
CWE-254 Security Features
Publication date:
14/09/2016
Last modified:
12/04/2025

Description

Microsoft Internet Explorer 9 through 11 mishandles .url files from the Internet zone, which allows remote attackers to bypass intended access restrictions via a crafted file, aka "Internet Explorer Security Feature Bypass."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*