CVE-2016-3222 is a critical memory corruption vulnerability in Microsoft Edge, allowing remote attackers to execute arbitrary code or cause a denial of service through a crafted website. With a CVSS score of 8.8 (HIGH), successful exploitation could lead to full compromise of the affected system, requiring user interaction to trigger. While not actively exploited in the wild, public exploit code exists on ExploitDB, and the vulnerability has garnered significant community and media attention, indicating its potential for abuse. Its high FAUCET Risk Score and EPSS percentile further emphasize the importance of patching this flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.