Vulnerability record · CVE-2016-0162 · published 12 April 2016
CVE-2016-0162: Internet Explorer JavaScript information disclosure exposes file existence
Microsoft · Internet Explorer
Microsoft Internet Explorer 9 through 11 fails to properly handle crafted JavaScript, allowing a remote attacker to determine whether specific files exist on a victim's system. The flaw is an information disclosure issue in the browser's handling of script-driven file probing, and it matters because it leaks local file presence that can support later, more targeted attacks.
Description
Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka "Internet Explorer Information Disclosure Vulnerability."
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Automated analysis
high priorityThe flaw is only medium severity by CVSS and limited to information disclosure, but its presence in CISA KEV with confirmed in-the-wild exploitation raises the operational priority.
What it is
Microsoft Internet Explorer 9 through 11 fails to properly handle crafted JavaScript, allowing a remote attacker to determine whether specific files exist on a victim's system. The flaw is an information disclosure issue in the browser's handling of script-driven file probing, and it matters because it leaks local file presence that can support later, more targeted attacks.
Impact
An attacker gains limited confidentiality impact: knowledge of whether particular files exist on the target host. No integrity or availability impact is described, and the leaked information is reconnaissance rather than direct code execution.
Attack surface
Reached over the network via a crafted web page or script that the victim must load in Internet Explorer 9 through 11; the CVSS vector shows no privileges required but user interaction required, so the victim must visit or open attacker-controlled content.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2022-05-24 with a 2022-06-14 remediation due date, indicating known exploitation in the wild; EPSS is 0.22088 (97.5th percentile), and no ransomware campaign use is documented.
What to do
- Apply the Microsoft MS16-037 security update for Internet Explorer, or the equivalent cumulative update for the affected platform.
- Retire Internet Explorer 9 through 11 and move users to a supported browser.
- Enforce the CISA KEV remediation due date of 2022-06-14 if the patch is not yet deployed.
- Restrict or block execution of untrusted JavaScript and untrusted web content in IE through policy where IE cannot be removed.
Detection
- Monitor for IE processes loading pages or scripts from untrusted or newly seen domains, especially where file-probing behavior is suspected.
- Review web proxy and DNS logs for IE user agents reaching low-reputation hosts that could host the crafted JavaScript.
- Hunt for suspicious script-driven file existence checks or unusual local file access patterns originating from browser processes.
- Track patch and version state of Internet Explorer 9 through 11 endpoints to confirm MS16-037 coverage.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2016-0162 to the Known Exploited Vulnerabilities catalog on 24 May 2022 as "Microsoft Internet Explorer Information Disclosure Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 14 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/85939 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1035521 | Broken LinkThird Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-037 | PatchVendor Advisory |
| http://www.securityfocus.com/bid/85939 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1035521 | Broken LinkThird Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-037 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-0162 | US Government Resource |
Track CVE-2016-0162 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-0162), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.