ZeroHour

CVE-2016-7200

KEV PoC ×3mass

Memory Corruption RCE in Microsoft Edge Chakra JavaScript Engine (CVE-2016-7200)

CISA: Microsoft Edge Memory Corruption Vulnerability

CVSS 3.1
8.8 high
EPSS
82%p100
Published
()
KEV added
AI analysis

CVE-2016-7200 is an out-of-bounds write (CWE-787) causing memory corruption in the Chakra JavaScript scripting engine used by Microsoft Edge. A remote attacker triggers it by luring a user to a crafted website, where malicious JavaScript processed by Chakra corrupts memory (the CVSS user-interaction requirement confirms browsing is the attack vector). Successful exploitation allows arbitrary code execution in the context of the logged-on user, or denial of service; confidentiality, integrity, and availability are all rated high. All users of the legacy (Chakra-based) Microsoft Edge browser at the time of the November 2016 disclosure were affected. Exploitation is confirmed in the wild: the flaw is in CISA KEV (added 2022-03-28), public proof-of-concept exploits exist, and it was added to the RIG and Sundown exploit kits, including campaigns delivering Cerber ransomware.

What to do: Apply the vendor's cumulative security updates for Microsoft Edge via Windows Update, per CISA's required action, and verify that all Windows 10 endpoints have post-November-2016 Edge updates installed. Note that the current Chromium-based Edge does not use the Chakra engine, so upgrading to a supported Edge/OS build eliminates the vulnerable component. Until patched, limit exposure by steering users away from untrusted websites, since drive-by exploit kits (RIG, Sundown) were actively weaponizing this flaw.

Affected
microsoft edge
Estimated exposure
masstens to hundreds of millions of Edge users at the time of disclosure (Edge was the default browser on Windows 10) — Chakra-based Edge shipped as the default browser on Windows 10, whose installed base was in the hundreds of millions in late 2016, so the population of users browsing attacker-reachable web content is plausibly on the order of tens to…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7201, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.

CISA Known Exploited Vulnerability
Affected
Microsoft Edge
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
edge
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news