RULE(RULE ID:313073)

Rule General Information
Release Date: 2017-09-01
Rule Name: Microsoft Edge Typedarray.sort Use After Free Vulnerability -2 (CVE-2016-7288)
Severity:
CVE ID:
Rule Protection Details
Description: The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability".
Impact: A use-after-free vulnerability can be exploited by an attacker in the vulnerable product. Successful exploit may cause some adverse consequences, such as crash of the product, execution of arbitrary code.
Affected OS: Windows
Reference: http://packetstormsecurity.com/files/140994/Microsoft-Edge-TypedArray.sort-Use-After-Free.html
SecurityTrackerID:1037444
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-145
SecurityFocusBID:94749
Solutions
Microsoft has released a patch MS16-145 to eliminate the vulnerability. The patch can be downloaded at http://technet.microsoft.com/security/bulletin/MS16-145