CVE-2016-7200
KEV PoC ×3massMemory Corruption RCE in Microsoft Edge Chakra JavaScript Engine (CVE-2016-7200)
CISA: Microsoft Edge Memory Corruption Vulnerability
CVE-2016-7200 is an out-of-bounds write (CWE-787) causing memory corruption in the Chakra JavaScript scripting engine used by Microsoft Edge. A remote attacker triggers it by luring a user to a crafted website, where malicious JavaScript processed by Chakra corrupts memory (the CVSS user-interaction requirement confirms browsing is the attack vector). Successful exploitation allows arbitrary code execution in the context of the logged-on user, or denial of service; confidentiality, integrity, and availability are all rated high. All users of the legacy (Chakra-based) Microsoft Edge browser at the time of the November 2016 disclosure were affected. Exploitation is confirmed in the wild: the flaw is in CISA KEV (added 2022-03-28), public proof-of-concept exploits exist, and it was added to the RIG and Sundown exploit kits, including campaigns delivering Cerber ransomware.
What to do: Apply the vendor's cumulative security updates for Microsoft Edge via Windows Update, per CISA's required action, and verify that all Windows 10 endpoints have post-November-2016 Edge updates installed. Note that the current Chromium-based Edge does not use the Chakra engine, so upgrading to a supported Edge/OS build eliminates the vulnerable component. Until patched, limit exposure by steering users away from untrusted websites, since drive-by exploit kits (RIG, Sundown) were actively weaponizing this flaw.
| microsoft edge | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7201, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.
- Affected
- Microsoft Edge
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- edge
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H