Think you have a false positive on this rule?

Sid 1-45213

Message

BROWSER-IE Microsoft Internet Explorer out of bounds read attempt

Summary

Impact

CVE-2016-7283:

CVSS base score 8.8

CVSS impact score 5.9

CVSS exploitability score 2.8

Confidentiality Impact HIGH

Integrity Impact HIGH

Availability Impact HIGH

Detailed information

CVE-2016-7283: Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

Affected systems

  • microsoft internet_explorer 9
  • microsoft internet_explorer 10
  • microsoft internet_explorer 11

Ease of attack

CVE-2016-7283:

Access Vector

Access Complexity

Authentication

False positives

False negatives

Corrective action

Upgrade to the latest non-affected version of the software.

Apply the appropriate vendor supplied patches.

Contributors

Additional References

  • technet.microsoft.com/en-us/security/bulletin/MS16-144