8.8
CVE-2016-7201
- EPSS 79.69%
- Veröffentlicht 10.11.2016 06:59:16
- Zuletzt bearbeitet 22.04.2026 16:05:09
- Erkennungen
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7200, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Edge Version -
Microsoft ≫ Windows 10 1507 Version -
Microsoft ≫ Windows 10 1511 Version -
Microsoft ≫ Windows 10 1607 Version -
Microsoft ≫ Windows Server 2016 Version -
Microsoft ≫ Windows 10 1511 Version -
Microsoft ≫ Windows 10 1607 Version -
Microsoft ≫ Windows Server 2016 Version -
28.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
Microsoft Edge Memory Corruption Vulnerability
SchwachstelleThe Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 79.69% | 0.996 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| NIST | 7.6 | 4.9 | 10 |
AV:N/AC:H/Au:N/C:C/I:C/A:C
|
| CISA-ADP | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')
The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.
http://www.securitytracker.com/id/1037245
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-129
http://packetstormsecurity.com/files/140382/Microsoft-Edge-chakra.dll-Information-Leak-Type-Confusion.html
https://github.com/theori-io/chakra-2016-11
https://www.exploit-db.com/exploits/40990/
http://www.securityfocus.com/bid/94038
https://www.exploit-db.com/exploits/40784/
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-7201