ZeroHour

CVE-2010-3962

KEVmass1

Uninitialized Memory Corruption RCE in Microsoft Internet Explorer

CISA: Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability

CVSS
EPSS
97%p100
Published
KEV added
AI analysis

Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that can allow a remote attacker to execute arbitrary code. As with other browser memory-corruption flaws, it is triggered when Internet Explorer processes attacker-controlled content such as a malicious or compromised web page, causing the browser to access memory that has not been properly initialized. A successful attacker gains code execution under the privileges of the logged-on user, which can enable installation of programs, theft of data, or ransomware staging (ransomware association for this CVE is currently unknown). Anyone still running Internet Explorer is affected; no specific version ranges were provided in the source data, and because IE is a largely retired product, exposure is concentrated in legacy Windows deployments. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-10-06, indicating exploitation in the wild, and EPSS assigns it a 96.9% probability of exploitation within 30 days (100th percentile); no public proof-of-concept is known.

What to do: Inventory your environment for any remaining Internet Explorer use, including legacy Windows systems and MSHTML/IE-mode dependencies, and apply Microsoft security updates addressing this vulnerability on any still-supported systems (the December 2010 cumulative security update MS10-090 resolves it). Where patching is not possible, follow the CISA KEV required action and BOD 22-01 guidance: apply vendor mitigations or discontinue use of Internet Explorer, given the 96.9% EPSS probability of exploitation within 30 days.

Affected
Microsoft Internet Explorer
Estimated exposure
massmillions of legacy Windows/IE installations (estimate) — Internet Explorer shipped with essentially every Windows release and historically ran on hundreds of millions of machines, so residual legacy Windows estates (Windows 7/XP/embedded systems, enterprise and government fleets) still in use…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CISA Known Exploited Vulnerability
Affected
Microsoft Internet Explorer
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Internet Explorer

In the news