CVE-2016-7209 is a spoofing vulnerability in Microsoft Edge that allows remote attackers to display crafted web content. With a CVSS score of 5.3 (MEDIUM), it requires user interaction and a high attack complexity, but can lead to high integrity impacts. While there is no known exploit code in Metasploit, Nuclei, or ExploitDB, it has garnered some community discussion and media coverage, including an article mentioning its exploitation by Russian hackers. Despite this, it is not listed in the KEV catalog and is currently considered inactive on the Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.