RULE(RULE ID:710512)

Rule General Information
Release Date: 2016-12-05
Rule Name: WEB-CLIENT Microsoft Edge Chakra Templatedforeachiteminrange Type Confusion Vulnerability (CVE-2016-7194)
Severity:
CVE ID:
Rule Protection Details
Description: The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability".
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows
Reference: MicrosoftSecurityBulletin:MS16-119
SecurityFocusBID:93399
SecurityTrackerID:1036993
Solutions
Microsoft has released a patch MS16-119 to eliminate the vulnerability. The patch can be downloaded at http://technet.microsoft.com/security/bulletin/MS16-119