CVE-2016-7241
HIGHMicrosoft Edge and Internet Explorer 11 - Remote Code Execution via Memory Corruption
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-7241. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit leverages an information leak in JSON.parse with a reviver function to expose memory pointers. The PoC manipulates the output object to contain a native array, causing the Walk function to write pointers that can be read by script.
Description
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."
Exploits (1)
This exploit leverages an information leak in JSON.parse with a reviver function to expose memory pointers. The PoC manipulates the output object to contain a native array, causing the Walk function to write pointers that can be read by script.
References (7)
Scores
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H