ZeroHour

CVE-2016-7201

KEV PoC ×3mass

Memory Corruption RCE in Microsoft Edge Chakra JavaScript Engine

CISA: Microsoft Edge Memory Corruption Vulnerability

CVSS 3.1
8.8 high
EPSS
80%p100
Published
()
KEV added
AI analysis

CVE-2016-7201 is a memory corruption flaw (CWE-843, type confusion) in the Chakra JavaScript scripting engine of Microsoft's legacy Edge browser. An attacker triggers it by luring a user to a specially crafted website viewed in Edge, where processing of malicious JavaScript corrupts memory. Successful exploitation yields remote code execution in the context of the current user (or a denial of service), giving the attacker the user's privileges on the endpoint. Users of the EdgeHTML-based Edge shipped with Windows at the time are affected; the source data does not specify exact version ranges. Exploitation is confirmed in the wild: the flaw was added to the Sundown Exploit Kit and used in RIG Exploit Kit campaigns delivering Cerber ransomware, it is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-28), and public proof-of-concept exploits are available.

What to do: Ensure any Windows devices still running legacy (EdgeHTML) Edge are fully patched via Windows Update — Microsoft fixed this flaw in its November 2016 cumulative security updates, per CISA KEV required actions — and migrate any remaining legacy-Edge users to current Chromium-based Edge, which does not use Chakra and is not affected. Because exploitation historically arrived via exploit kits (Sundown, RIG) on drive-by web pages, maintain web filtering and ad blocking and keep browsers current on all endpoints.

Affected
microsoft edge
Estimated exposure
masshundreds of millions of Windows 10 devices historically (legacy Edge shipped preinstalled with Windows); likely far fewer remaining legacy-Edge users today — Legacy Microsoft Edge was preinstalled on every Windows 10 device, giving an install base of hundreds of millions at disclosure, though the browser has since been retired in favor of Chromium-based Edge, leaving a much smaller current…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7200, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.

CISA Known Exploited Vulnerability
Affected
Microsoft Edge
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
edge
Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news