Researchers published a detailed analysis and proof-of-concept exploit for Microsoft bulletin MS16-063, showing how a flaw in Internet Explorer's jscript9.dll can be turned into code execution on Internet Explorer 11 running Windows 7. The vulnerability stems from improper handling of detached ArrayBuffer objects in TypedArray and DataView operations, creating a use-after-free condition when functions such as DirectGetItem, DirectSetItem, GetValue, and SetValue access freed backing memory after an ArrayBuffer is detached via postMessage.
The published research describes an exploitation path that converts the bug into arbitrary read/write primitives and then into shellcode execution through heap manipulation, a fake virtual function table, ROP, and VirtualProtect. A companion GitHub repository released a public HTML proof of concept that can be served over HTTP and opened in a vulnerable browser, although the authors noted it is not fully reliable. The researchers also reported that the demonstrated technique does not work on Windows 8.1 and later because Control Flow Guard blocks the indirect-call method used in the exploit.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
On 2016-06-27, Theori made a GitHub repository available for a proof-of-concept exploit targeting the jscript9.dll TypedArray/DataView memory corruption issue associated with MS16-063. The repository said the exploit was tested against Internet Explorer 11 on Windows 7 and provided basic reproduction steps.
On 2016-06-26, Theori published an analysis of Microsoft bulletin MS16-063 describing a use-after-free flaw in jscript9.dll involving detached ArrayBuffer handling in TypedArray and DataView operations. The write-up included a proof-of-concept and an Internet Explorer 11 on Windows 7 exploitation path using heap manipulation, a fake vtable, ROP, and VirtualProtect.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.