CVE-2016-3353: Microsoft Internet Explorer
High severity, CVSS 8.3. EPSS: 11.8% chance of exploitation in the next 30 days.
Microsoft Internet Explorer 9 through 11 mishandles .url files from the Internet zone, which allows remote attackers to bypass intended access restrictions via a crafted file, aka "Internet Explorer Security Feature Bypass."
Affected products
- Microsoft Internet Explorer: version 9 only; version 10 only; version 11 only
Published 2016-09-14. Last modified 2026-06-17.