Exploitation Summary
EIP tracks 2 public exploits for CVE-2016-0199. PoCs published by Skylined, LeoonZHANG.
AI-analyzed exploit summary This exploit leverages a type confusion vulnerability in MSIE 11's garbage collector, allowing an attacker to manipulate a vftable pointer by setting an attribute with an invalid nodeValue, leading to potential arbitrary code execution.
Description
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0200 and CVE-2016-3211.
Exploits (2)
This exploit leverages a type confusion vulnerability in MSIE 11's garbage collector, allowing an attacker to manipulate a vftable pointer by setting an attribute with an invalid nodeValue, leading to potential arbitrary code execution.
The repository contains only a minimal README with no exploit code or technical details. It is a placeholder with no functional content.
References (7)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H