The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7201, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243
Published Nov 10, 2016 ·Due Apr 18, 2022
7.7
HIGHCVSS 4.0
EPSS 82.78%
Description
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7201, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.
Affected products
No data.
Running on/with
- n/a
- n/a
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
AV:N/AC:H/Au:N/C:C/I:C/A:C
Date Added
Mar 28, 2022
Patch Due
Apr 18, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Feb 10, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (30 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 82.78% (0.82779) | 99.66th | v5 (v2026.06.15) |
| Jun 15, 2026 | 82.49% (0.82490) | 99.62th | v5 (v2026.06.15) |
| Apr 18, 2026 | 88.15% (0.88153) | 99.49th | v4 (v2025.03.14) |
| Sep 28, 2025 | 89.39% (0.89395) | 99.53th | v4 (v2025.03.14) |
| Sep 2, 2025 | 88.34% (0.88345) | 99.48th | v4 (v2025.03.14) |
| Mar 30, 2025 | 89.92% (0.89915) | 99.56th | v4 (v2025.03.14) |
| Mar 29, 2025 | 91.91% (0.91912) | 99.65th | v4 (v2025.03.14) |
| Mar 28, 2025 | 90.38% (0.90382) | 99.59th | v4 (v2025.03.14) |
| Mar 27, 2025 | 92.18% (0.92176) | 99.70th | v4 (v2025.03.14) |
| Mar 20, 2025 | 90.38% (0.90382) | 99.61th | v4 (v2025.03.14) |
| Mar 19, 2025 | 92.18% (0.92176) | 99.71th | v4 (v2025.03.14) |
| Mar 17, 2025 | 90.38% (0.90382) | 99.59th | v4 (v2025.03.14) |
| Dec 12, 2024 | 95.77% (0.95772) | 99.51th | v3 (v2023.03.01) |
| Sep 2, 2024 | 95.51% (0.95507) | 99.44th | v3 (v2023.03.01) |
| Aug 12, 2024 | 94.22% (0.94215) | 99.23th | v3 (v2023.03.01) |
| Aug 11, 2024 | 92.63% (0.92634) | 99.06th | v3 (v2023.03.01) |
| Jul 10, 2024 | 94.91% (0.94905) | 99.31th | v3 (v2023.03.01) |
| May 25, 2024 | 97.16% (0.97163) | 99.81th | v3 (v2023.03.01) |
| Feb 11, 2024 | 97.15% (0.97146) | 99.77th | v3 (v2023.03.01) |
| Jan 3, 2024 | 96.76% (0.96756) | 99.59th | v3 (v2023.03.01) |
| Nov 23, 2023 | 96.65% (0.96645) | 99.53th | v3 (v2023.03.01) |
| Oct 14, 2023 | 97.10% (0.97102) | 99.70th | v3 (v2023.03.01) |
| Sep 1, 2023 | 97.16% (0.97161) | 99.71th | v3 (v2023.03.01) |
| Jul 24, 2023 | 97.34% (0.97337) | 99.81th | v3 (v2023.03.01) |
| Jun 14, 2023 | 97.34% (0.97343) | 99.82th | v3 (v2023.03.01) |
| May 7, 2023 | 97.41% (0.97408) | 99.87th | v3 (v2023.03.01) |
| Mar 28, 2023 | 97.37% (0.97372) | 99.81th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.39% (0.97389) | 99.81th | v3 (v2023.03.01) |
| Mar 6, 2023 | 91.08% (0.91084) | 99.88th | v2 (v2022.01.01) |
| Feb 4, 2022 | 91.08% (0.91084) | 99.85th | v2 (v2022.01.01) |
References (14)
- http://packetstormsecurity.com/files/140382/Microsoft-Edge-chakra.dll-Information-Leak-Type-Confusion.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/93968 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1037245 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-129 vendor-advisoryx_refsource_MSPatchVendor Advisory
- https://github.com/advisories/GHSA-5whg-j5fv-xcm2 Advisory
- https://github.com/chakra-core/ChakraCore/commit/c2787ef8fdb7401922e9ec6540e4e5895d11c631
- https://github.com/chakra-core/ChakraCore/pull/1982
- https://github.com/theori-io/chakra-2016-11 x_refsource_MISCExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-7200
- https://web.archive.org/web/20210123184454/http://www.securityfocus.com/bid/93968
- https://web.archive.org/web/20211126224744/http://www.securitytracker.com/id/1037245
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-7200 government-resourceUS Government Resource
- https://www.exploit-db.com/exploits/40785 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/40990 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
Change history (0)
No recorded changes yet.