First published: Fri Oct 14 2016(Updated: )
The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as demonstrated by the Chakra JavaScript engine, aka "Scripting Engine Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/Microsoft.ChakraCore | <1.2.1 | 1.2.1 |
Microsoft Edge Beta | ||
Internet Explorer | =9 | |
Internet Explorer | =10 | |
Internet Explorer | =11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3382 has a severity rating of critical due to its potential for remote code execution and denial of service.
To fix CVE-2016-3382, ensure that your installation of Microsoft Internet Explorer or Microsoft Edge is updated to the latest version.
CVE-2016-3382 affects Microsoft Internet Explorer versions 9, 10, and 11, as well as Microsoft Edge.
CVE-2016-3382 can be exploited to execute arbitrary code or cause memory corruption leading to denial of service through crafted websites.
While the best mitigation for CVE-2016-3382 is to update affected software, using alternative browsers can serve as a temporary workaround.