CVE-2016-0162
Microsoft Internet Explorer Information Disclosure Vulnerability
Description
CVE-2016-0162 is an information disclosure vulnerability in Microsoft Internet Explorer caused by improper handling of JavaScript. The vulnerability allows an attacker to detect the presence of specific files on a user's computer by luring the victim to a specially crafted website. This file detection capability enables attackers to fingerprint target systems, identify installed security software, and tailor follow-up attacks. CVE-2016-0162 has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, and its EPSS percentile of 97.2% indicates a very high likelihood of exploitation.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| microsoft | internet explorer | 9; 10; 11 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
References
- http://www.securityfocus.com/bid/85939(Broken Link, Third Party Advisory, VDB Entry)
- http://www.securitytracker.com/id/1035521(Broken Link, Third Party Advisory, VDB Entry)
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-037(Patch, Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-0162(US Government Resource)
Weakness Type
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CWE-200 describes situations where a product unintentionally reveals sensitive information to parties who should not have access to it. In CVE-2016-0162, Internet Explorer's improper handling of JavaScript operations allows remote attackers to probe for the existence of specific files on the victim's local file system through a crafted web page, leaking system configuration details.
Learn more: CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor
Impact Analysis
CVE-2016-0162 primarily impacts confidentiality by enabling remote attackers to determine whether specific files exist on the target system. The vulnerability is exploitable through the network when a user visits a crafted web page, requiring user interaction but no authentication. While the direct impact is limited to information disclosure, this reconnaissance capability is highly valuable in exploit kit operations where attackers use file detection to identify installed software versions, security products, and virtual machine artifacts before deciding whether to deliver a full exploit payload. The EPSS percentile of 97.2% confirms significant real-world exploitation activity, and CISA has added CVE-2016-0162 to the KEV catalog, reflecting its use in active attack campaigns.
Exploit Maturity
CISA has confirmed active exploitation of CVE-2016-0162 in the wild and added it to the Known Exploited Vulnerabilities catalog with a remediation deadline of June 14, 2022. The EPSS percentile of 97.2% indicates very high exploitation probability. This vulnerability was used in exploit kit campaigns for target fingerprinting, where attackers checked for the presence of security tools, antivirus software, and analysis environment artifacts before delivering secondary payloads. The reconnaissance value of this vulnerability made it a standard component in several exploit kits active during 2016 and subsequent years.
Remediation
- Apply Microsoft security updates as directed by the vendor. This is the required remediation action per CISA's KEV catalog entry for CVE-2016-0162.
- Migrate away from Internet Explorer to a modern, supported browser such as Microsoft Edge, Google Chrome, or Mozilla Firefox, as Internet Explorer has reached end of life.
- If Internet Explorer must remain temporarily in use, restrict JavaScript execution on untrusted sites through Internet Explorer Security Zones and Group Policy settings.
- Deploy web content filtering and intrusion prevention systems to block access to known exploit kit domains and detect exploitation attempts.
- Monitor endpoint security logs for signs of browser-based reconnaissance attempts, including unusual JavaScript execution patterns and attempts to probe the local file system.
Technical Details
CVE-2016-0162 exploits a flaw in how Internet Explorer handles JavaScript operations related to file system interaction. The vulnerability falls under CWE-200 (Exposure of Sensitive Information), where the browser fails to properly restrict JavaScript's ability to detect the existence of local files. Through carefully crafted JavaScript code on a malicious web page, an attacker can use timing side channels or error-based probing techniques to determine whether specific files exist on the victim's local disk. The attack is network-based, requiring the victim to navigate to the attacker's page, but requires no authentication. This file detection technique was a critical component in exploit kit kill chains, where the attacker's landing page would first probe for security software and analysis tools before deciding whether to serve an exploit or redirect the user away to avoid detection.
Frequently Asked Questions
Is CVE-2016-0162 being actively exploited?
Yes, CVE-2016-0162 has been actively exploited in the wild. CISA has confirmed active exploitation and added it to the KEV catalog. The EPSS percentile of 97.2% reflects very high exploitation probability, driven by its widespread use in exploit kit campaigns for target fingerprinting.
What products are affected by CVE-2016-0162?
CVE-2016-0162 affects Microsoft Internet Explorer. Multiple versions of Internet Explorer across Windows platforms are vulnerable. Internet Explorer has reached end of life and should be replaced with a modern browser.
How do I fix CVE-2016-0162?
Apply the Microsoft security update for CVE-2016-0162. The most effective long-term remediation is migrating away from Internet Explorer to a modern browser. See the Remediation section for detailed steps.
How severe is CVE-2016-0162?
CVE-2016-0162 is an information disclosure vulnerability that enables file detection on target systems. While not directly enabling code execution, its EPSS percentile of 97.2% reflects high exploitation activity due to its role as a reconnaissance tool in exploit kit campaigns that target Internet Explorer users.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.