CVE-2016-7200: Microsoft Edge Memory Corruption Vulnerability
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7201, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.
Other sources
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nuget/Microsoft.ChakraCoreto a version that resolves this vulnerability.Fixed in 1.2.2
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7200?
CVE-2016-7200 has a high severity rating due to the potential for remote code execution and denial of service.
How do I fix CVE-2016-7200?
To fix CVE-2016-7200, update Microsoft Edge to the latest version available.
What types of attacks can exploit CVE-2016-7200?
CVE-2016-7200 can be exploited by remote attackers through crafted websites to execute arbitrary code.
Which versions of Microsoft Edge are affected by CVE-2016-7200?
All versions of Microsoft Edge prior to the fix are affected by CVE-2016-7200.
Is CVE-2016-7200 specific to a particular operating system?
CVE-2016-7200 primarily affects Microsoft Edge on Windows platforms.