Executive brief
The Chakra JavaScript scripting engine in Microsoft Edge contains a memory corruption vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service. The flaw is triggered when a user visits a specially crafted website, leading to an out-of-bounds write (CWE-787).
Affected products
- Microsoft Edge Windows 10, Windows Server 2016
- Microsoft Chakra JavaScript Engine
Timeline
- 2016-11-08: patched: Microsoft released security bulletin MS16-129 to address the issue.
- 2022-03-28: kev added: CISA added this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog.
- 2022-03-28: disclosed