7.6
CVE-2016-0189
- EPSS 93.71%
- Veröffentlicht 11.05.2016 01:59:30
- Zuletzt bearbeitet 22.04.2026 16:31:49
- Erkennungen
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0187.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Explorer Version 9
Microsoft ≫ Internet Explorer Version 10
Microsoft ≫ Internet Explorer Version 11 Update -
Microsoft ≫ Windows 10 1507 Version -
Microsoft ≫ Windows 10 1511 Version -
Microsoft ≫ Windows 7 Version - Update sp1
Microsoft ≫ Windows 8.1 Version -
Microsoft ≫ Windows Rt 8.1 Version -
Microsoft ≫ Windows Server 2008 Version r2 Update sp1 HwPlatform x64
Microsoft ≫ Windows Server 2012 Version r2
Microsoft ≫ Windows 10 1511 Version -
Microsoft ≫ Windows 7 Version - Update sp1
Microsoft ≫ Windows 8.1 Version -
Microsoft ≫ Windows Rt 8.1 Version -
Microsoft ≫ Windows Server 2008 Version r2 Update sp1 HwPlatform x64
Microsoft ≫ Windows Server 2012 Version r2
28.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
Microsoft Internet Explorer Memory Corruption Vulnerability
SchwachstelleThe Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 93.71% | 0.998 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| NIST | 7.6 | 4.9 | 10 |
AV:N/AC:H/Au:N/C:C/I:C/A:C
|
| CISA-ADP | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
http://www.securitytracker.com/id/1035820
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-051
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-053
http://www.securityfocus.com/bid/90012
https://www.exploit-db.com/exploits/40118/
https://www.virusbulletin.com/virusbulletin/2017/01/journey-and-evolution-god-mode-2016-cve-2016-0189/
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-0189