CVE-2016-3206
published 2016-06-16CVE-2016-3206: The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to…
PriorityP274high7.5CVSS 3.0
AVNACHPRNUIRSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
14.66%
96.3th percentile
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3205 and CVE-2016-3207.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | jscript | — | — |
| microsoft | vbscript | — | — |
| microsoft | vbscript | — | — |
| msrc | internet_explorer_10 | — | — |
| msrc | internet_explorer_11 | — | — |
| msrc | internet_explorer_9 | — | — |
| msrc | vbscript_5.7 | — | — |
| msrc | vbscript_5.8 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability resides in the VBScript engine (vbscript.dll); monitor for memory corruption triggered by crafted web content loaded through Internet Explorer or the browser rendering engine hosted in Office documents/ActiveX controls. ↗
- →Watch for ActiveX controls marked 'safe for initialization' being used as an attack vector to deliver the exploit through non-browser surfaces such as Office documents hosting the browser rendering engine. ↗
- →Check file version of vbscript.dll and jscript.dll on endpoints; versions starting with 5.8 (e.g., 5.8.7600.16385) on unpatched systems are vulnerable and should be flagged. ↗
- →Monitor for exploitation attempts via compromised or attacker-controlled websites serving crafted content; threat intel rates exploitation as 'More Likely' for both latest and older software releases. ↗
- ·The workaround (restricting ACLs on vbscript.dll and jscript.dll) will break legitimate websites that rely on VBScript or JScript; apply only as a temporary measure on systems that cannot be patched immediately. ↗
- ·Patch applicability differs by IE version: IE 9/10/11 systems should apply MS16-063 (Internet Explorer Cumulative Update), while IE 7 and earlier systems should apply MS16-069; applying the wrong bulletin will leave the system unpatched. ↗
- ·Both JScript.dll and VBScript.dll are shipped together in the cumulative update package, but only the specific components listed as affected software are actually fixed by the security patches in this bulletin. ↗
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vulncheck7.5HIGH
vendor_msrc7.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cvcc-85m3-r674: The Microsoft (1) JScript 5
ghsa_unreviewed·2022-05-14·CVSS 7.5
CVE-2016-3207 [HIGH] CWE-119 GHSA-cvcc-85m3-r674: The Microsoft (1) JScript 5
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3205 and CVE-2016-3206.
GHSA
GHSA-w52f-8m83-9j69: The Microsoft (1) JScript 5
ghsa_unreviewed·2022-05-14·CVSS 7.5
CVE-2016-3205 [HIGH] CWE-119 GHSA-w52f-8m83-9j69: The Microsoft (1) JScript 5
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3206 and CVE-2016-3207.
GHSA
GHSA-qvwv-w8j8-wm24: The Microsoft (1) JScript 5
ghsa_unreviewed·2022-05-14·CVSS 7.5
CVE-2016-3206 [HIGH] CWE-119 GHSA-qvwv-w8j8-wm24: The Microsoft (1) JScript 5
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3205 and CVE-2016-3207.
VulnCheck
Microsoft jscript Improper Input Validation
vulncheck·2016·CVSS 7.5
CVE-2016-3205 [HIGH] Microsoft jscript Improper Input Validation
Microsoft jscript Improper Input Validation
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3206 and CVE-2016-3207.
Affected: Microsoft jscript
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://dl.acm.org/doi/pdf/10.1145/3465481.3465758
VulnCheck
Microsoft jscript Improper Input Validation
vulncheck·2016·CVSS 7.5
CVE-2016-3206 [HIGH] Microsoft jscript Improper Input Validation
Microsoft jscript Improper Input Validation
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3205 and CVE-2016-3207.
Affected: Microsoft jscript
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://dl.acm.org/doi/pdf/10.1145/3465481.3465758
VulnCheck
Microsoft jscript Improper Input Validation
vulncheck·2016·CVSS 7.5
CVE-2016-3207 [HIGH] Microsoft jscript Improper Input Validation
Microsoft jscript Improper Input Validation
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3205 and CVE-2016-3206.
Affected: Microsoft jscript
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://dl.acm.org/doi/pdf/10.1145/3465481.3465758
Microsoft
Scripting Engine Memory Corruption Vulnerability
vendor_msrc·2016-06-14·CVSS 7.5
CVE-2016-3205 [HIGH] Scripting Engine Memory Corruption Vulnerability
Scripting Engine Memory Corruption Vulnerability
Description: A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
In a web-based attack scenario, an attacker could host a specially crafted website d
Microsoft
Scripting Engine Memory Corruption Vulnerability
vendor_msrc·2016-06-14·CVSS 7.5
CVE-2016-3207 [HIGH] Scripting Engine Memory Corruption Vulnerability
Scripting Engine Memory Corruption Vulnerability
Description: A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
In a web-based attack scenario, an attacker could host a specially crafted website d
Microsoft
Scripting Engine Memory Corruption Vulnerability
vendor_msrc·2016-06-14·CVSS 7.5
CVE-2016-3206 [HIGH] Scripting Engine Memory Corruption Vulnerability
Scripting Engine Memory Corruption Vulnerability
Description: A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
In a web-based attack scenario, an attacker could host a specially crafted website d
No detection rules found.
No public exploits indexed.
http://www.securitytracker.com/id/1036096http://www.securitytracker.com/id/1036097https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-063https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-069http://www.securitytracker.com/id/1036096http://www.securitytracker.com/id/1036097https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-063https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-069
2016-06-16
Published
Exploited in the wild