CVE-2016-3207
published 2016-06-16CVE-2016-3207: The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to…
PriorityP274high7.5CVSS 3.0
AVNACHPRNUIRSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
17.40%
96.8th percentile
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3205 and CVE-2016-3206.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | jscript | — | — |
| microsoft | vbscript | — | — |
| microsoft | vbscript | — | — |
| msrc | internet_explorer_10 | — | — |
| msrc | internet_explorer_11 | — | — |
| msrc | internet_explorer_9 | — | — |
| msrc | vbscript_5.7 | — | — |
| msrc | vbscript_5.8 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability resides in the VBScript engine (vbscript.dll); monitor for memory corruption triggered by crafted web content loaded through Internet Explorer or the browser rendering engine hosted in Office documents/ActiveX controls. ↗
- →Watch for ActiveX controls marked 'safe for initialization' being used as an attack vector to deliver the exploit through Office documents or applications hosting the browser rendering engine. ↗
- →Check file version of vbscript.dll and jscript.dll under %systemroot%\system32 (or %windir%\syswow64 on 64-bit); unpatched vulnerable versions start with 5.7 or 5.8 (e.g., 5.8.x). ↗
- ·The vulnerability and its mitigations apply differently depending on the Internet Explorer version installed. IE 9–11 are addressed by MS16-063; IE 7 and earlier are addressed by MS16-069. Ensure the correct bulletin is applied for the IE version in your environment. ↗
- ·Both JScript.dll and VBScript.dll are shipped together in the cumulative update package, but only the VBScript engine components are the subject of the CVE-2016-3207 security fix. ↗
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vulncheck7.5HIGH
vendor_msrc7.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cvcc-85m3-r674: The Microsoft (1) JScript 5
ghsa_unreviewed·2022-05-14·CVSS 7.5
CVE-2016-3207 [HIGH] CWE-119 GHSA-cvcc-85m3-r674: The Microsoft (1) JScript 5
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3205 and CVE-2016-3206.
GHSA
GHSA-w52f-8m83-9j69: The Microsoft (1) JScript 5
ghsa_unreviewed·2022-05-14·CVSS 7.5
CVE-2016-3205 [HIGH] CWE-119 GHSA-w52f-8m83-9j69: The Microsoft (1) JScript 5
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3206 and CVE-2016-3207.
GHSA
GHSA-qvwv-w8j8-wm24: The Microsoft (1) JScript 5
ghsa_unreviewed·2022-05-14·CVSS 7.5
CVE-2016-3206 [HIGH] CWE-119 GHSA-qvwv-w8j8-wm24: The Microsoft (1) JScript 5
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3205 and CVE-2016-3207.
VulnCheck
Microsoft jscript Improper Input Validation
vulncheck·2016·CVSS 7.5
CVE-2016-3205 [HIGH] Microsoft jscript Improper Input Validation
Microsoft jscript Improper Input Validation
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3206 and CVE-2016-3207.
Affected: Microsoft jscript
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://dl.acm.org/doi/pdf/10.1145/3465481.3465758
VulnCheck
Microsoft jscript Improper Input Validation
vulncheck·2016·CVSS 7.5
CVE-2016-3206 [HIGH] Microsoft jscript Improper Input Validation
Microsoft jscript Improper Input Validation
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3205 and CVE-2016-3207.
Affected: Microsoft jscript
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://dl.acm.org/doi/pdf/10.1145/3465481.3465758
VulnCheck
Microsoft jscript Improper Input Validation
vulncheck·2016·CVSS 7.5
CVE-2016-3207 [HIGH] Microsoft jscript Improper Input Validation
Microsoft jscript Improper Input Validation
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3205 and CVE-2016-3206.
Affected: Microsoft jscript
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://dl.acm.org/doi/pdf/10.1145/3465481.3465758
Microsoft
Scripting Engine Memory Corruption Vulnerability
vendor_msrc·2016-06-14·CVSS 7.5
CVE-2016-3205 [HIGH] Scripting Engine Memory Corruption Vulnerability
Scripting Engine Memory Corruption Vulnerability
Description: A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
In a web-based attack scenario, an attacker could host a specially crafted website d
Microsoft
Scripting Engine Memory Corruption Vulnerability
vendor_msrc·2016-06-14·CVSS 7.5
CVE-2016-3207 [HIGH] Scripting Engine Memory Corruption Vulnerability
Scripting Engine Memory Corruption Vulnerability
Description: A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
In a web-based attack scenario, an attacker could host a specially crafted website d
Microsoft
Scripting Engine Memory Corruption Vulnerability
vendor_msrc·2016-06-14·CVSS 7.5
CVE-2016-3206 [HIGH] Scripting Engine Memory Corruption Vulnerability
Scripting Engine Memory Corruption Vulnerability
Description: A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
In a web-based attack scenario, an attacker could host a specially crafted website d
No detection rules found.
No public exploits indexed.
http://www.securitytracker.com/id/1036096http://www.securitytracker.com/id/1036097https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-063https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-069http://www.securitytracker.com/id/1036096http://www.securitytracker.com/id/1036097https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-063https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-069
2016-06-16
Published
Exploited in the wild