Vulnerability record · CVE-2016-3247 · published 14 September 2016
CVE-2016-3247: Microsoft Edge and Internet Explorer memory corruption RCE
Microsoft · Edge
Microsoft Internet Explorer 11 and Microsoft Edge contain a memory corruption flaw that a crafted web site can trigger. Successful exploitation allows arbitrary code execution in the browser's context, or a denial of service crash. It matters because browsers are a primary user-facing attack surface and the flaw affects widely deployed Microsoft browsers.
Description
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution in widely used browsers with a public exploit and very high EPSS, though exploitation requires user interaction and no KEV listing is present.
What it is
Microsoft Internet Explorer 11 and Microsoft Edge contain a memory corruption flaw that a crafted web site can trigger. Successful exploitation allows arbitrary code execution in the browser's context, or a denial of service crash. It matters because browsers are a primary user-facing attack surface and the flaw affects widely deployed Microsoft browsers.
Impact
An attacker can execute arbitrary code with the privileges of the browsing user, or crash the browser to cause a denial of service. Code execution in the browser context can lead to further compromise of the host depending on mitigations and user privileges.
Attack surface
Reached over the network via a crafted web site rendered by Internet Explorer 11 or Microsoft Edge. No authentication is required, but user interaction is needed because the victim must visit or be directed to the malicious page (CVSS vector UI:R).
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.71478, 99.384th percentile) and a public Exploit-DB entry (40797) exists, indicating exploit code is available. No ransomware group usage is documented in the record.
What to do
- Apply the Microsoft security updates MS16-104 (Internet Explorer) and MS16-105 (Edge) as the primary fix.
- Retire or restrict Internet Explorer 11 where possible and standardize on a supported, current browser.
- Enforce browser hardening such as Enhanced Protected Mode / AppContainer and EMET or Windows Defender Exploit Guard mitigations where applicable.
- Block or filter known malicious and untrusted sites at the network and email gateway layers to reduce drive-by exposure.
- Keep endpoint detection and browser versions current so memory corruption exploitation attempts are more likely to be caught.
Detection
- Monitor for browser process crashes (iexplore.exe, MicrosoftEdge.exe) that cluster around visits to untrusted sites.
- Hunt for child processes spawned by browser processes, which can indicate successful exploitation and payload execution.
- Review proxy and DNS logs for access to known exploit-hosting or malicious domains tied to this vulnerability.
- Correlate endpoint telemetry for suspicious memory or shellcode behavior in browser processes with recent browsing activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-3247 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-3247), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.