Vulnerability CVE-2016-3202


Published: 2016-06-15   Modified: 2016-06-16

Description:
The Microsoft (1) Chakra JavaScript, (2) JScript, and (3) VBScript engines, as used in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability."

Type:

CWE-20

(Improper Input Validation)

CVSS2 => (AV:N/AC:H/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.6/10
10/10
4.9/10
Exploit range
Attack complexity
Authentication
Remote
High
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Microsoft -> Chakra javascript 
Microsoft -> Jscript 
Microsoft -> Vbscript 

 References:
http://www.securitytracker.com/id/1036096
http://www.securitytracker.com/id/1036099
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-063
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-068

Copyright 2024, cxsecurity.com

 

Back to Top