Vulnerability record · CVE-2016-3222 · published 16 June 2016
CVE-2016-3222: Microsoft Edge memory corruption allows remote code execution
Microsoft · Edge
Microsoft Edge contains a memory corruption flaw (CWE-119) that a remote attacker can trigger through a crafted web site, leading to arbitrary code execution or denial of service. The vulnerability is reachable over the network with no privileges required, though the victim must interact with the page. It matters because successful exploitation can compromise the browser process and potentially the host.
Description
Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability."
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability and high EPSS, but exploitation requires user interaction and the flaw is dated with a vendor patch available.
What it is
Microsoft Edge contains a memory corruption flaw (CWE-119) that a remote attacker can trigger through a crafted web site, leading to arbitrary code execution or denial of service. The vulnerability is reachable over the network with no privileges required, though the victim must interact with the page. It matters because successful exploitation can compromise the browser process and potentially the host.
Impact
An attacker can execute arbitrary code in the context of the Edge browser or crash it, causing denial of service. Code execution could allow further compromise of the user's session and data.
Attack surface
Reached remotely over the network via a crafted web site rendered by Microsoft Edge. No authentication is required, but user interaction (visiting the page) is needed per the CVSS vector UI:R.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.56767, 99th percentile) and public references include an Exploit-DB entry and a ZDI advisory, indicating public exploit information exists.
What to do
- Apply the Microsoft security update MS16-068 for Microsoft Edge.
- Keep Edge and the underlying Windows platform fully patched.
- Restrict or monitor browsing to untrusted sites and enforce SmartScreen/Exploit Protection where feasible.
- Consider disabling or limiting unnecessary browser features and add-ons that expand the attack surface.
Detection
- Monitor for Edge process crashes and abnormal memory corruption indicators in endpoint telemetry.
- Hunt for suspicious child processes spawned by MicrosoftEdge.exe, especially script interpreters or command shells.
- Review proxy and DNS logs for access to known exploit-hosting or malvertising domains.
- Correlate Exploit-DB/ZDI reference activity with endpoint alerts for Edge exploitation attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-3222 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-3222), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.