CVE-2016-0111
HIGHMicrosoft Internet Explorer 9-11 and Edge - Remote Code Execution via Memory Corruption
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-0111. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit targets a use-after-free vulnerability in Microsoft Edge (CVE-2016-0111) by manipulating SVG elements and triggering a DOMAttrModified event, leading to memory corruption. The PoC demonstrates the vulnerability by adopting a node into a new document, causing a heap corruption.
Description
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0105, CVE-2016-0107, CVE-2016-0112, and CVE-2016-0113.
Exploits (1)
This exploit targets a use-after-free vulnerability in Microsoft Edge (CVE-2016-0111) by manipulating SVG elements and triggering a DOMAttrModified event, leading to memory corruption. The PoC demonstrates the vulnerability by adopting a node into a new document, causing a heap corruption.
References (6)
Scores
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H