Executive brief
A type confusion vulnerability in the Chakra JavaScript scripting engine within Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service. The flaw is triggered when a user visits a specially crafted website, leading to memory corruption.
Affected products
- Microsoft Edge -
- Microsoft Windows 10 1507 -
- Microsoft Windows 10 1511 -
- Microsoft Windows 10 1607 -
- Microsoft Windows Server 2016 -
Timeline
- 2016-11-08: patched: Microsoft released security bulletin MS16-129 to address the issue.
- 2022-03-28: kev added: CISA added this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog.
- 2022-03-28: disclosed: NVD publication date.