CVE-2016-3222

HIGH EXPLOITED

Microsoft Edge - Remote Code Execution via Memory Corruption

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2016-3222 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Skylined.

AI-analyzed exploit summary The document describes a memory corruption vulnerability in Microsoft Edge (CVE-2016-3222) triggered by crafted JavaScript code. It includes multiple proof-of-concept snippets that cause access violations or NULL pointer dereferences, with analysis suggesting potential for arbitrary code execution under specific conditions.

Description

Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability."

Exploits (1)

exploitdb WRITEUP
by Skylined · textdoswindows
https://www.exploit-db.com/exploits/40880

The document describes a memory corruption vulnerability in Microsoft Edge (CVE-2016-3222) triggered by crafted JavaScript code. It includes multiple proof-of-concept snippets that cause access violations or NULL pointer dereferences, with analysis suggesting potential for arbitrary code execution under specific conditions.

Classification
Writeup 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Microsoft Edge (32-bit and 64-bit)
No auth needed
Prerequisites: Target user must visit a malicious webpage
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Various Sources x_refsource_misc
http://blog.skylined.nl/20161205001.html
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/40880/
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-16-371
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1036099
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/91094
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2016/Dec/16

Scores

CVSS v3 8.8
EPSS 0.5677
EPSS Percentile 98.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2021-08-17
CWE
CWE-119
Status published
Products (1)
microsoft/edge
Published Jun 16, 2016
Tracked Since Feb 18, 2026