HTTP: Microsoft Windows Edge CVE-2016-7200 Code Execution

A type confusion vulnerability was discovered within Microsoft EDGE. Successful exploitation could allow an attacker to cause arbitrary remote code execution into the context of running application.

Extended Description

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7201, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.

References

CVE: CVE-2016-7200

Short Name
HTTP:STC:IE:CVE-2016-7200-RCE
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2016-7200 Code Edge Execution Microsoft Windows
Release Date
11/08/2016
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3827
False Positive
Unknown
CVSS Score

7.6

Found a potential security threat?