CVE-2016-7200
Summary
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7201, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.
Impact & exploitability
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products we track (1)
Recommendation
This vulnerability is being actively exploited in the wild — patch affected products urgently. Open any affected product above for its exact safe version.
Official patch: https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-129 ↗
Additional information
- NVD record
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-129Patch
- http://packetstormsecurity.com/files/140382/Microsoft-Edge-chakra.dll-Information-Leak-Type-Confusion.htmlAdvisory
- http://www.securityfocus.com/bid/93968Advisory
- http://www.securitytracker.com/id/1037245Advisory
- http://packetstormsecurity.com/files/140382/Microsoft-Edge-chakra.dll-Information-Leak-Type-Confusion.htmlAdvisory
- https://github.com/theori-io/chakra-2016-11Advisory
- https://www.exploit-db.com/exploits/40785/Advisory
- https://www.exploit-db.com/exploits/40990/Advisory