⚠ Actively exploited
Added to CISA KEV on 2022-03-28. Federal agencies required to patch by 2022-04-18. Required action: Apply updates per vendor instructions..

CVE-2016-7200Out-of-bounds Write in Microsoft Edge ON Windows 10 Version 1511 FOR 32-bit Systems

Severity
8.8HIGHNVD
NVD7.5
EPSS
88.2%
top 0.51%
CISA KEV
KEV
Added 2022-03-28
Due 2022-04-18
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedNov 10
KEV addedMar 28
KEV dueApr 18
Latest updateMay 14
CISA Required Action: Apply updates per vendor instructions.

Description

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7201, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Patches

🔴Vulnerability Details

19
GHSA
ChakraCore RCE Vulnerability2022-05-14
GHSA
ChakraCore RCE Vulnerability2022-05-14
OSV
ChakraCore RCE Vulnerability2022-05-14
GHSA
ChakraCore RCE Vulnerability2022-05-14
GHSA
ChakraCore RCE Vulnerability2022-05-14

💥Exploits & PoCs

2
Exploit-DB
Microsoft Edge (Windows 10) - 'chakra.dll' Information Leak / Type Confusion Remote Code Execution2017-01-05
Exploit-DB
Microsoft Edge - 'Array.filter' Information Leak2016-11-18

🔍Detection Rules

6
Suricata
ET EXPLOIT Possible Microsoft Edge Chakra.dll Type Confusion (CVE-2016-7200 CVE-2016-7201) B6412017-01-06
Suricata
ET EXPLOIT Possible Microsoft Edge Chakra.dll Type Confusion (CVE-2016-7200 CVE-2016-7201) B6432017-01-06
Suricata
ET EXPLOIT Possible Microsoft Edge Chakra.dll Type Confusion (CVE-2016-7200 CVE-2016-7201) B6422017-01-06
Suricata
ET EXPLOIT Possible Microsoft Edge Chakra.dll Type Confusion (CVE-2016-7200 CVE-2016-7201) Observed in SunDown EK 22017-01-06
Suricata
ET EXPLOIT Possible Microsoft Edge Chakra.dll Type Confusion (CVE-2016-7200 CVE-2016-7201) Observed in SunDown EK 32017-01-06

📋Vendor Advisories

2
CISA
Microsoft Edge Memory Corruption Vulnerability2022-03-28
Microsoft
Scripting Engine Memory Corruption Vulnerability2016-11-08

🕵️Threat Intelligence

1
Zscaler
Zscaler found Multiple Security Vulnerabilities | 11-08-2016