vendor:
Windows 10
by:
Scott Bell
7,5
CVSS
HIGH
Memory Corruption Vulnerability
119
CWE
Product Name: Windows 10
Affected Version From: Microsoft Windows 10, Microsoft Windows Server 2016
Affected Version To: Microsoft Windows 10, Microsoft Windows Server 2016
Patch Exists: YES
Related CWE: CVE-2016-7202
CPE: o:microsoft:windows_10
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2016
Microsoft Edge Scripting Engine Memory Corruption Vulnerability (MS16-129)
A memory corruption vulnerability was identified in the Microsoft Edge Chakra JavaScript engine which could allow a malicious user to remotely execute arbitrary code on a vulnerable user’s machine, in the context of the current user. Exploitation of this vulnerability requires a user to visit a page containing specially crafted JavaScript. Users can generally be lured to visit web pages via email, instant message or links on the internet. Vulnerabilities like this are often hosted on legitimate websites which have been compromised by other means.
Mitigation:
Users should avoid visiting untrusted websites and clicking on suspicious links.