Executive brief
The Microsoft JScript and VBScript engines in Internet Explorer 9 through 11 contain a memory corruption vulnerability. Remote attackers can exploit this via a crafted website to execute arbitrary code or cause a denial of service.
Affected products
- Microsoft JScript 5.8
- Microsoft VBScript 5.7
- Microsoft VBScript 5.8
- Microsoft Internet Explorer 9
- Microsoft Internet Explorer 10
- Microsoft Internet Explorer 11
Timeline
- 2016-05-10: patched: Microsoft released security bulletins MS16-051 and MS16-053.
- 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2022-03-28: disclosed: NVD publication date.