CVE-2016-3205
published 2016-06-16CVE-2016-3205: The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to…
PriorityP273high7.5CVSS 3.0
AVNACHPRNUIRSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
14.66%
96.3th percentile
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3206 and CVE-2016-3207.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | jscript | — | — |
| microsoft | vbscript | — | — |
| microsoft | vbscript | — | — |
| msrc | internet_explorer_10 | — | — |
| msrc | internet_explorer_11 | — | — |
| msrc | internet_explorer_9 | — | — |
| msrc | vbscript_5.7 | — | — |
| msrc | vbscript_5.8 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerable scripting engine DLL: check jscript.dll file version starting with 5.8 in %systemroot%\system32 (or syswow64 on 64-bit) to identify exposure to CVE-2016-3205 ↗
- →Attack vector is a crafted web site delivered through Internet Explorer (versions 9–11) or via an ActiveX control embedded in an Office document; monitor for IE rendering engine invocations from Office processes or unusual ActiveX 'safe for initialization' control loads ↗
- →Exploitation likelihood is rated 'More Likely' for both latest and older software releases — prioritise detection and patching on all IE 9/10/11 systems ↗
- →CVE-2016-3205 is addressed by MS16-069 for IE 7 and earlier (KB patches), and by MS16-063 cumulative update for IE 8 and later; absence of these KBs indicates a vulnerable host ↗
- ·The vulnerability affects JScript 5.8 AND VBScript 5.7 and 5.8; both jscript.dll and vbscript.dll are shipped together in the cumulative update packages, but only the components listed as affected software are patched by each respective bulletin ↗
- ·Workaround (ACL restriction on vbscript.dll/jscript.dll) will break websites relying on VBScript or JScript; paths differ between 32-bit (%windir%\system32) and 64-bit (%windir%\syswow64) systems ↗
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vulncheck7.5HIGH
vendor_msrc7.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cvcc-85m3-r674: The Microsoft (1) JScript 5
ghsa_unreviewed·2022-05-14·CVSS 7.5
CVE-2016-3207 [HIGH] CWE-119 GHSA-cvcc-85m3-r674: The Microsoft (1) JScript 5
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3205 and CVE-2016-3206.
GHSA
GHSA-w52f-8m83-9j69: The Microsoft (1) JScript 5
ghsa_unreviewed·2022-05-14·CVSS 7.5
CVE-2016-3205 [HIGH] CWE-119 GHSA-w52f-8m83-9j69: The Microsoft (1) JScript 5
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3206 and CVE-2016-3207.
GHSA
GHSA-qvwv-w8j8-wm24: The Microsoft (1) JScript 5
ghsa_unreviewed·2022-05-14·CVSS 7.5
CVE-2016-3206 [HIGH] CWE-119 GHSA-qvwv-w8j8-wm24: The Microsoft (1) JScript 5
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3205 and CVE-2016-3207.
VulnCheck
Microsoft jscript Improper Input Validation
vulncheck·2016·CVSS 7.5
CVE-2016-3205 [HIGH] Microsoft jscript Improper Input Validation
Microsoft jscript Improper Input Validation
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3206 and CVE-2016-3207.
Affected: Microsoft jscript
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://dl.acm.org/doi/pdf/10.1145/3465481.3465758
VulnCheck
Microsoft jscript Improper Input Validation
vulncheck·2016·CVSS 7.5
CVE-2016-3206 [HIGH] Microsoft jscript Improper Input Validation
Microsoft jscript Improper Input Validation
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3205 and CVE-2016-3207.
Affected: Microsoft jscript
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://dl.acm.org/doi/pdf/10.1145/3465481.3465758
VulnCheck
Microsoft jscript Improper Input Validation
vulncheck·2016·CVSS 7.5
CVE-2016-3207 [HIGH] Microsoft jscript Improper Input Validation
Microsoft jscript Improper Input Validation
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3205 and CVE-2016-3206.
Affected: Microsoft jscript
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://dl.acm.org/doi/pdf/10.1145/3465481.3465758
Microsoft
Scripting Engine Memory Corruption Vulnerability
vendor_msrc·2016-06-14·CVSS 7.5
CVE-2016-3205 [HIGH] Scripting Engine Memory Corruption Vulnerability
Scripting Engine Memory Corruption Vulnerability
Description: A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
In a web-based attack scenario, an attacker could host a specially crafted website d
Microsoft
Scripting Engine Memory Corruption Vulnerability
vendor_msrc·2016-06-14·CVSS 7.5
CVE-2016-3207 [HIGH] Scripting Engine Memory Corruption Vulnerability
Scripting Engine Memory Corruption Vulnerability
Description: A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
In a web-based attack scenario, an attacker could host a specially crafted website d
Microsoft
Scripting Engine Memory Corruption Vulnerability
vendor_msrc·2016-06-14·CVSS 7.5
CVE-2016-3206 [HIGH] Scripting Engine Memory Corruption Vulnerability
Scripting Engine Memory Corruption Vulnerability
Description: A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
In a web-based attack scenario, an attacker could host a specially crafted website d
No detection rules found.
No public exploits indexed.
http://www.securitytracker.com/id/1036096http://www.securitytracker.com/id/1036097https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-063https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-069http://www.securitytracker.com/id/1036096http://www.securitytracker.com/id/1036097https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-063https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-069
2016-06-16
Published
Exploited in the wild