CVE-2016-3201: Microsoft Edge

Medium severity, CVSS 6.5. EPSS: 23.6% chance of exploitation in the next 30 days.

Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, and Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted PDF document, aka "Windows PDF Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3215.

Affected products

  • Microsoft Edge: affected versions not specified
  • Microsoft Windows 10: affected versions not specified; version 1511 only
  • Microsoft Windows 8.1: any version
  • Microsoft Windows Server 2012: any version; affected versions not specified

Published 2016-06-16. Last modified 2026-06-17.