The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to determine the existence of local files via unspecified vectors, aka "Microsoft Browser Information Disclosure Vulnerability."
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-129 | vendor advisory |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-142 | vendor advisory |
http://www.securityfocus.com/bid/94065 | vdb entry |
http://www.securitytracker.com/id/1037245 | vdb entry |