ZeroHour

CVE-2010-0249

KEVmass

Use-After-Free Remote Code Execution in Microsoft Internet Explorer

CISA: Microsoft Internet Explorer Use-After-Free Vulnerability

CVSS
EPSS
92%p100
Published
KEV added
AI analysis

Microsoft Internet Explorer contains a use-after-free flaw (CWE-416) in which the browser accesses a pointer to an object that has already been deleted, a defect historically associated with the January 2010 'Aurora' targeted attacks. The flaw is triggered when a user simply visits an attacker-crafted or attacker-controlled web page that forces the browser to free an in-use object and then dereference the dangling pointer during page rendering. Successful exploitation gives a remote attacker the ability to execute arbitrary code in the security context of the logged-on user, potentially installing programs; viewing, changing, or deleting data; or creating new accounts. Anyone running Internet Explorer is affected, especially organizations still relying on the now end-of-life/end-of-service browser on legacy Windows systems, which CISA says should discontinue use if mitigations are not applied. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-05-20 and EPSS assigns a 91.9% probability of exploitation within 30 days (100th percentile), although no public proof-of-concept is cataloged.

What to do: Per CISA's KEV required action, apply Microsoft's mitigations: the January 2010 out-of-band cumulative security update for Internet Explorer (MS10-002) remediates this flaw, with workarounds including disabling Active Scripting or setting the Internet and Local intranet security zones to High. Inventory any systems still invoking Internet Explorer (legacy Windows builds and intranet apps) and migrate them to Microsoft Edge or another supported browser, discontinuing IE use entirely where mitigations are unavailable.

Affected
Microsoft Internet Explorer
Estimated exposure
masshundreds of millions of legacy Windows/IE installs (IE held roughly 60% of global browser share when the flaw was disclosed) — Estimated from Internet Explorer's historically dominant install base on Windows (~60% browser market share at the time of the 2010 disclosure) and the long tail of legacy Windows systems and intranet applications that still depend on IE.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CISA Known Exploited Vulnerability
Affected
Microsoft Internet Explorer
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Internet Explorer
Weakness
CWE-416

In the news