Vulnerability record · CVE-2016-3288 · published 9 August 2016
CVE-2016-3288: Internet Explorer 11 memory corruption allows remote code execution
Microsoft · Internet Explorer
Microsoft Internet Explorer 11 contains a memory corruption flaw (CWE-119) that a remote attacker can trigger with a crafted web page, leading to arbitrary code execution in the context of the browser. It is a distinct issue from CVE-2016-3290 and was addressed in Microsoft bulletin MS16-095. Because IE 11 was widely deployed and the flaw is reachable through ordinary browsing, it remains relevant to unpatched or legacy systems.
Description
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code via a crafted web page, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3290.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution with a high EPSS score and public exploit code, tempered by the requirement for user interaction and the availability of a patch since 2016.
What it is
Microsoft Internet Explorer 11 contains a memory corruption flaw (CWE-119) that a remote attacker can trigger with a crafted web page, leading to arbitrary code execution in the context of the browser. It is a distinct issue from CVE-2016-3290 and was addressed in Microsoft bulletin MS16-095. Because IE 11 was widely deployed and the flaw is reachable through ordinary browsing, it remains relevant to unpatched or legacy systems.
Impact
An attacker who successfully exploits the flaw can execute arbitrary code with the privileges of the logged-on user. If that user has administrative rights, the attacker could take full control of the host, including installing programs and modifying or deleting data.
Attack surface
Reached over the network via a crafted web page rendered by Internet Explorer 11; the CVSS vector indicates no privileges are required but user interaction is required, meaning the victim must visit or open the malicious page. No authentication is needed on the attacker's side.
Exploitation
The record is not listed in CISA KEV, but EPSS is high (0.518 probability, 98.9th percentile) and an Exploit-DB entry (40253) exists, indicating public exploit code is available. No ransomware group usage is documented.
What to do
- Apply the MS16-095 cumulative security update for Internet Explorer or the equivalent current patch level.
- Retire or migrate off Internet Explorer 11 where possible, since it is no longer supported on current Windows versions.
- Enforce Enhanced Protected Mode and 64-bit IE process isolation on any remaining IE 11 deployments.
- Block or restrict untrusted web content through network filtering and proxy controls for legacy IE users.
- Reduce user privileges so browsing occurs without administrative rights.
Detection
- Monitor for IE 11 (iexplore.exe) crashes or abnormal child process creation, especially processes spawned from the browser.
- Alert on exploit-db signature 40253 or related crafted-page indicators in web proxy and IDS logs.
- Hunt for suspicious script or executable drops originating from iexplore.exe in user-writable directories.
- Review endpoint telemetry for memory-corruption exploitation patterns such as unexpected ROP-like behavior in IE processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-3288 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-3288), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.