The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7200, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243
Published Nov 10, 2016 ·Due Apr 18, 2022
7.7
HIGHCVSS 4.0
EPSS 80.00%
Description
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7200, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.
Affected products
No data.
Running on/with
- n/a
- n/a
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
AV:N/AC:H/Au:N/C:C/I:C/A:C
Date Added
Mar 28, 2022
Patch Due
Apr 18, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Feb 10, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (20 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 80.00% (0.80004) | 99.61th | v5 (v2026.06.15) |
| Jun 15, 2026 | 79.69% (0.79687) | 99.56th | v5 (v2026.06.15) |
| Mar 17, 2025 | 89.74% (0.89736) | 99.55th | v4 (v2025.03.14) |
| Dec 12, 2024 | 96.18% (0.96182) | 99.59th | v3 (v2023.03.01) |
| Aug 12, 2024 | 95.33% (0.95332) | 99.40th | v3 (v2023.03.01) |
| Aug 11, 2024 | 61.61% (0.61614) | 97.86th | v3 (v2023.03.01) |
| Jul 10, 2024 | 95.91% (0.95911) | 99.48th | v3 (v2023.03.01) |
| May 25, 2024 | 97.16% (0.97163) | 99.81th | v3 (v2023.03.01) |
| Feb 11, 2024 | 97.15% (0.97146) | 99.77th | v3 (v2023.03.01) |
| Jan 3, 2024 | 96.76% (0.96756) | 99.59th | v3 (v2023.03.01) |
| Nov 23, 2023 | 96.65% (0.96645) | 99.53th | v3 (v2023.03.01) |
| Oct 14, 2023 | 97.10% (0.97102) | 99.70th | v3 (v2023.03.01) |
| Sep 1, 2023 | 97.16% (0.97161) | 99.71th | v3 (v2023.03.01) |
| Jul 24, 2023 | 97.34% (0.97337) | 99.81th | v3 (v2023.03.01) |
| Jun 14, 2023 | 97.34% (0.97343) | 99.82th | v3 (v2023.03.01) |
| May 7, 2023 | 97.41% (0.97408) | 99.87th | v3 (v2023.03.01) |
| Mar 28, 2023 | 97.37% (0.97372) | 99.81th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.39% (0.97389) | 99.81th | v3 (v2023.03.01) |
| Mar 6, 2023 | 91.08% (0.91084) | 99.88th | v2 (v2022.01.01) |
| Feb 4, 2022 | 91.08% (0.91084) | 99.85th | v2 (v2022.01.01) |
References (14)
- http://packetstormsecurity.com/files/140382/Microsoft-Edge-chakra.dll-Information-Leak-Type-Confusion.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/94038 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1037245 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-129 vendor-advisoryx_refsource_MSPatchVendor Advisory
- https://github.com/advisories/GHSA-4f5g-j7wg-7w8j Advisory
- https://github.com/chakra-core/ChakraCore/commit/c2787ef8fdb7401922e9ec6540e4e5895d11c631
- https://github.com/chakra-core/ChakraCore/pull/1982
- https://github.com/theori-io/chakra-2016-11 x_refsource_MISCExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-7201
- https://web.archive.org/web/20210123185125/http://www.securityfocus.com/bid/94038
- https://web.archive.org/web/20211126224744/http://www.securitytracker.com/id/1037245
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-7201 government-resourceUS Government Resource
- https://www.exploit-db.com/exploits/40784 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/40990 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
Change history (0)
No recorded changes yet.