RULE(RULE ID:321943)

Rule General Information
Release Date: 2019-06-25
Rule Name: Microsoft Internet Explorer and Edge Font Lang Parameter Use After Free Vulnerability (CVE-2016-3297)
Severity:
CVE ID:
Rule Protection Details
Description: Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."
Impact: A use-after-free vulnerability can be exploited by an attacker in the vulnerable product. Successful exploit may cause some adverse consequences, such as crash of the product, execution of arbitrary code.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:92829
SecurityTrackerID:1036789
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-105
SecurityTrackerID:1036788
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://technet.microsoft.com/library/security/ms16-104