{
  "id": "cve-2016-3298",
  "cveID": "CVE-2016-3298",
  "vendor": "Microsoft",
  "product": "Internet Explorer",
  "vulnerabilityName": "Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability",
  "shortDescription": "An information disclosure vulnerability exists when the Microsoft Internet Messaging API improperly handles objects in memory. An attacker who successfully exploited this vulnerability could allow the attacker to test for the presence of files on disk.",
  "requiredAction": "Apply updates per vendor instructions.",
  "dateAdded": "2022-05-24",
  "dueDate": "2022-06-14",
  "knownRansomware": false,
  "cwes": [
    "CWE-200"
  ],
  "notes": "https://nvd.nist.gov/vuln/detail/CVE-2016-3298",
  "sources": [
    {
      "label": "NVD",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-3298"
    },
    {
      "label": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
    },
    {
      "label": "nvd.nist.gov",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-3298"
    }
  ],
  "cvss": {
    "score": 6.5,
    "severity": "MEDIUM",
    "version": "3.1",
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
  },
  "epss": {
    "score": 0.3279,
    "percentile": 0.98245
  },
  "timeline": [
    {
      "date": "2022-05-24",
      "event": "Added to the CISA KEV catalog"
    },
    {
      "date": "2022-06-14",
      "event": "CISA remediation due date (BOD 22-01)"
    }
  ],
  "status": "past due"
}