CVE-2016-3273: Microsoft Edge
Medium severity, CVSS 5.3. EPSS: 14.2% chance of exploitation in the next 30 days.
The XSS Filter in Microsoft Internet Explorer 9 through 11 and Microsoft Edge does not properly restrict JavaScript code, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
Affected products
- Microsoft Edge: any version
- Microsoft Internet Explorer: version 9 only; version 10 only; version 11 only
Published 2016-07-13. Last modified 2026-06-17.