Junglewise Threat Intelligence

CVE-2016-7201: ChakraCore RCE Vulnerability

CVE-2016-7201 · Severity: critical · CVSS 3 · Exploited in the wild · Published 2022-05-14

Technologies: Microsoft Windows Server 2016, Microsoft Windows 10 1607, Microsoft Edge, Microsoft Internet Explorer. Vendors: Microsoft, NuGet.

Executive brief

A type confusion vulnerability in the Chakra JavaScript scripting engine within Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service. The flaw is triggered when a user visits a specially crafted website, leading to memory corruption.

Affected products

  • Microsoft Edge -
  • Microsoft Windows 10 1507 -
  • Microsoft Windows 10 1511 -
  • Microsoft Windows 10 1607 -
  • Microsoft Windows Server 2016 -

Timeline

  • 2016-11-08: patched: Microsoft released security bulletin MS16-129 to address the issue.
  • 2022-03-28: kev added: CISA added this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog.
  • 2022-03-28: disclosed: NVD publication date.

Related threats