cbcvebase.
CVE-2016-3206
published 2016-06-16

CVE-2016-3206: The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to…

PriorityP274high7.5CVSS 3.0
AVNACHPRNUIRSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
14.66%
96.3th percentile
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3205 and CVE-2016-3207.

Affected

8 ranges
VendorProductVersion rangeFixed in
microsoftjscript
microsoftvbscript
microsoftvbscript
msrcinternet_explorer_10
msrcinternet_explorer_11
msrcinternet_explorer_9
msrcvbscript_5.7
msrcvbscript_5.8

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability resides in the VBScript engine (vbscript.dll); monitor for memory corruption triggered by crafted web content loaded through Internet Explorer or the browser rendering engine hosted in Office documents/ActiveX controls.
  • Watch for ActiveX controls marked 'safe for initialization' being used as an attack vector to deliver the exploit through non-browser surfaces such as Office documents hosting the browser rendering engine.
  • Check file version of vbscript.dll and jscript.dll on endpoints; versions starting with 5.8 (e.g., 5.8.7600.16385) on unpatched systems are vulnerable and should be flagged.
  • Monitor for exploitation attempts via compromised or attacker-controlled websites serving crafted content; threat intel rates exploitation as 'More Likely' for both latest and older software releases.
  • ·The workaround (restricting ACLs on vbscript.dll and jscript.dll) will break legitimate websites that rely on VBScript or JScript; apply only as a temporary measure on systems that cannot be patched immediately.
  • ·Patch applicability differs by IE version: IE 9/10/11 systems should apply MS16-063 (Internet Explorer Cumulative Update), while IE 7 and earlier systems should apply MS16-069; applying the wrong bulletin will leave the system unpatched.
  • ·Both JScript.dll and VBScript.dll are shipped together in the cumulative update package, but only the specific components listed as affected software are actually fixed by the security patches in this bulletin.

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vulncheck7.5HIGH
vendor_msrc7.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.