CVE-2016-7201: Microsoft Edge Memory Corruption Vulnerability
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7200, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.
Other sources
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nuget/Microsoft.ChakraCoreto a version that resolves this vulnerability.Fixed in 1.2.2
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7201?
CVE-2016-7201 has a severity rating of critical due to the potential for remote code execution.
How do I fix CVE-2016-7201?
To mitigate CVE-2016-7201, update Microsoft Edge to the latest version provided by Microsoft.
What software does CVE-2016-7201 affect?
CVE-2016-7201 primarily affects Microsoft Edge and the Chakra JavaScript scripting engine.
Can CVE-2016-7201 cause a denial of service?
Yes, CVE-2016-7201 can lead to denial of service conditions due to memory corruption.
What type of vulnerability is CVE-2016-7201?
CVE-2016-7201 is classified as a memory corruption vulnerability in the scripting engine.