Cyber Resilience

CVE-2016-0162

Microsoft Internet Explorer 10 … 9

CISA KEVActive ExploitationEUVD Exploited
Published
12 April 2016
Modified
21 April 2026
KEV Added
24 May 2022
Patch / advisory
CVSS Score v3.1 4.3
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS Score 0.22 97th percentile
Risk Priority 75 floored blend · peak EPSS

Summary

CVE-2016-0162 is a medium-severity an unspecified weakness vulnerability in Microsoft Internet Explorer. Its CVSS base score is 4.3 (Medium).

Operationally, ranked in the top 3% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

Microsoft Internet Explorer versions 9 through 11 are affected by an information disclosure vulnerability that permits remote attackers to determine the existence of files on a target system through the use of specially crafted JavaScript code. The issue is tracked as CVE-2016-0162 with a CVSS v3 base score of 4.3 and is described by Microsoft as the "Internet Explorer Information Disclosure Vulnerability."

An unauthenticated remote attacker can exploit the flaw when a user visits a malicious or compromised website containing the crafted script. Successful exploitation reveals limited information about file presence without requiring user interaction beyond normal browsing, though it does not allow direct code execution or modification of data.

Microsoft security bulletin MS16-037 addresses the vulnerability and supplies the corresponding security updates for affected versions of Internet Explorer. The bulletin outlines patch installation as the primary mitigation step along with standard guidance on applying updates promptly.

EU & UK References

Vulnerability Data

Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka "Internet Explorer Information Disclosure Vulnerability."

CWE(s)
KEV Date Added
24 May 2022

Related Threats

CVEs Like This One

CVE-2016-3298Same product: Microsoft Internet Explorerboth on KEV
CVE-2016-0167Same product: Microsoft Windows 10 1507both on KEV
CVE-2016-0165Same product: Microsoft Windows 10 1507both on KEV
CVE-2016-3351Same product: Microsoft Internet Explorerboth on KEV
CVE-2017-0149Same product: Microsoft Internet Explorerboth on KEV
CVE-2017-0059Same product: Microsoft Internet Explorerboth on KEV
CVE-2016-0189Same product: Microsoft Internet Explorerboth on KEV
CVE-2016-3309Same product: Microsoft Windows 10 1507both on KEV
CVE-2015-2502Same product: Microsoft Internet Explorerboth on KEV
CVE-2016-3393Same product: Microsoft Windows 10 1507both on KEV

Affected Assets

microsoft
internet explorer
10, 11, 9

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References