Vulnerability record · CVE-2016-0199 · published 16 June 2016
CVE-2016-0199: Internet Explorer memory corruption allows remote code execution
Microsoft · Internet Explorer
Internet Explorer 9 through 11 contains a memory corruption flaw (CWE-119) reachable through a crafted web site. A remote attacker can trigger it to execute arbitrary code in the context of the browsing user or crash the browser. It is a distinct issue from CVE-2016-0200 and CVE-2016-3211.
Description
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0200 and CVE-2016-3211.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution with no privileges required and public exploit code, though exploitation requires user interaction and the affected browser is legacy.
What it is
Internet Explorer 9 through 11 contains a memory corruption flaw (CWE-119) reachable through a crafted web site. A remote attacker can trigger it to execute arbitrary code in the context of the browsing user or crash the browser. It is a distinct issue from CVE-2016-0200 and CVE-2016-3211.
Impact
Successful exploitation gives the attacker arbitrary code execution with the privileges of the logged-on user, or a denial of service through browser crash. Code execution at user privilege level can lead to full system compromise depending on the victim's rights.
Attack surface
Reached over the network via a crafted web page rendered in Internet Explorer 9-11; the CVSS vector shows no privileges required but user interaction required, meaning the victim must visit or open the malicious page. No authentication is needed by the attacker.
Exploitation
Not listed in CISA KEV, but EPSS is 0.50996 (98.9th percentile) and public references carry Exploit tags, including an Exploit-DB entry, indicating public exploit code exists.
What to do
- Apply the Microsoft MS16-063 security update for Internet Explorer 9, 10 and 11 immediately.
- Retire Internet Explorer 9-11 where possible and migrate users to a supported browser.
- Enforce EMET or equivalent exploit mitigations on systems that must still run Internet Explorer.
- Restrict or block browsing to untrusted sites and disable ActiveX and other legacy IE features not required for business use.
Detection
- Monitor for iexplore.exe crashes and memory corruption events (e.g., Windows Error Reporting, Application Error 1000) on endpoints.
- Hunt for iexplore.exe spawning child processes such as cmd.exe, powershell.exe or script hosts, which is abnormal for normal browsing.
- Review proxy and DNS logs for access to known exploit-hosting or malvertising domains tied to IE exploit kits.
- Check patch state of Internet Explorer/MS16-063 across the estate to find unpatched hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-0199 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-0199), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.