Junglewise Threat Intelligence

CVE-2016-7200: Microsoft Edge Memory Corruption Vulnerability

CVE-2016-7200 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-03-28

Technologies: Microsoft Edge, Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

The Chakra JavaScript scripting engine in Microsoft Edge contains a memory corruption vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service. The flaw is triggered when a user visits a specially crafted website, leading to an out-of-bounds write (CWE-787).

Affected products

  • Microsoft Edge Windows 10, Windows Server 2016
  • Microsoft Chakra JavaScript Engine

Timeline

  • 2016-11-08: patched: Microsoft released security bulletin MS16-129 to address the issue.
  • 2022-03-28: kev added: CISA added this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog.
  • 2022-03-28: disclosed

Related threats