ZeroHour

CVE-2010-0806

KEVlarge

Use-After-Free RCE in Microsoft Internet Explorer (CVE-2010-0806)

CISA: Microsoft Internet Explorer Use-After-Free Vulnerability

CVSS
EPSS
82%p100
Published
KEV added
AI analysis

Microsoft Internet Explorer contains a use-after-free (resource management) flaw in which the browser accesses an invalid pointer after an object has been deleted, leaving a dangling pointer. A remote attacker can trigger the flaw by luring a user of a vulnerable Internet Explorer version to attacker-controlled or malicious web content; the dangling-pointer access can be leveraged to execute arbitrary code with the victim user's privileges. Any system still running the affected Internet Explorer builds is exposed; the flaw dates to the 2010 era, when vendor advisories (cumulative update MS10-018, March 2010) addressed it in Internet Explorer 6 and 7, and CISA notes the impacted product may be end-of-life. Exploitation is confirmed in the wild: the flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2026-05-20 (ransomware use unknown), and EPSS assigns an 82.2% probability of exploitation within 30 days; no public proof-of-concept is cataloged.

What to do: Apply mitigations per Microsoft's vendor instructions within the BOD 22-01 timeframe, which for affected builds means the MS10-018 (March 2010) cumulative Internet Explorer update; because IE 6/7 (and IE generally) are end-of-life/retired, CISA also permits discontinuing use of the product. Inventory the estate for Internet Explorer 6/7 on legacy Windows XP and embedded or unmanaged systems, and migrate any remaining users to a supported, currently patched browser rather than relying on the retired IE client.

Affected
Microsoft Internet ExplorerVersion ranges not enumerated in the KEV data (listed simply as Microsoft Internet Explorer); Microsoft's March 2010 advisory MS10-018 addressed this flaw in In
Estimated exposure
large~100,000 to 1,000,000 residual legacy installations still running vulnerable IE 6/7 builds (out of the hundreds of millions of IE users when the flaw was… — IE 6 and 7 shipped with Windows XP, whose installed base ran to hundreds of millions of machines at the time of the 2010 advisory, but both those browser versions and the OS are long end-of-life, so the currently exposed population is only…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CISA Known Exploited Vulnerability
Affected
Microsoft Internet Explorer
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Internet Explorer
Weakness
CWE-399

In the news