CVE-2016-0024Improper Restriction of Operations within the Bounds of a Memory Buffer in Microsoft Edge ON Windows 10 FOR 32-bit Systems

Severity
8.8HIGHNVD
EPSS
32.4%
top 3.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13
Latest updateMay 14

Description

The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code via unspecified vectors, aka "Scripting Engine Memory Corruption Vulnerability."

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

🔴Vulnerability Details

2
OSV
ChakraCore RCE Vulnerability2022-05-14
GHSA
ChakraCore RCE Vulnerability2022-05-14

📋Vendor Advisories

2
VMware
vSphere Data Protection (VDP) updates address SSH Key-Based authentication issue2016-12-20
Microsoft
Scripting Engine Memory Corruption Vulnerability2016-01-12

🕵️Threat Intelligence

3
Talos
Microsoft Patch Tuesday - January 20162016-01-12
Talos
Microsoft Patch Tuesday - January 20162016-01-12
Zscaler
Zscaler found Multiple Security Vulnerabilities | 01-12-2016

💬Community

1
Bugzilla
CVE-2016-8642 CVE-2016-8643 CVE-2016-8644 moodle: Multiple security issues2016-12-02