CVE-2016-7201
KEV PoC ×3massMemory Corruption RCE in Microsoft Edge Chakra JavaScript Engine
CISA: Microsoft Edge Memory Corruption Vulnerability
CVE-2016-7201 is a memory corruption flaw (CWE-843, type confusion) in the Chakra JavaScript scripting engine of Microsoft's legacy Edge browser. An attacker triggers it by luring a user to a specially crafted website viewed in Edge, where processing of malicious JavaScript corrupts memory. Successful exploitation yields remote code execution in the context of the current user (or a denial of service), giving the attacker the user's privileges on the endpoint. Users of the EdgeHTML-based Edge shipped with Windows at the time are affected; the source data does not specify exact version ranges. Exploitation is confirmed in the wild: the flaw was added to the Sundown Exploit Kit and used in RIG Exploit Kit campaigns delivering Cerber ransomware, it is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-28), and public proof-of-concept exploits are available.
What to do: Ensure any Windows devices still running legacy (EdgeHTML) Edge are fully patched via Windows Update — Microsoft fixed this flaw in its November 2016 cumulative security updates, per CISA KEV required actions — and migrate any remaining legacy-Edge users to current Chromium-based Edge, which does not use Chakra and is not affected. Because exploitation historically arrived via exploit kits (Sundown, RIG) on drive-by web pages, maintain web filtering and ad blocking and keep browsers current on all endpoints.
| microsoft edge | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7200, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.
- Affected
- Microsoft Edge
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- edge
- Weakness
- CWE-843
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H