vulnerability

Microsoft Windows: CVE-2016-3321: Internet Explorer Information Disclosure Vulnerability

Severity
2
CVSS
(AV:L/AC:M/Au:N/C:P/I:N/A:N)
Published
Aug 9, 2016
Added
Jun 10, 2024
Modified
Oct 14, 2025

Description

Microsoft Internet Explorer 10 and 11 load different files for attempts to open a file:// URL depending on whether the file exists, which allows local users to enumerate files via vectors involving a file:// URL and an HTML5 sandbox iframe, aka "Internet Explorer Information Disclosure Vulnerability."

Solutions

microsoft-windows-windows_10-1507-kb3176492microsoft-windows-windows_10-1511-kb3176493microsoft-windows-windows_10-1607-kb3176495
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.

    Rapid7 Vulnerability Database