CVE-2016-3202

HIGH

Microsoft Chakra JavaScript, JScript, and VBScript - Remote Code Execution via Memory Corruption

Title source: llm
STIX 2.1

Description

The Microsoft (1) Chakra JavaScript, (2) JScript, and (3) VBScript engines, as used in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability."

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1036099
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1036096

Scores

CVSS v3 7.5
EPSS 0.1492
EPSS Percentile 94.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-119 CWE-20
Status published
Products (4)
microsoft/chakra_javascript
microsoft/jscript
microsoft/vbscript
nuget/Microsoft.ChakraCore 0 - 1.2.0.0NuGet
Published Jun 16, 2016
Tracked Since Feb 18, 2026