CVE-2010-3962
KEVmass1Uninitialized Memory Corruption RCE in Microsoft Internet Explorer
CISA: Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability
Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that can allow a remote attacker to execute arbitrary code. As with other browser memory-corruption flaws, it is triggered when Internet Explorer processes attacker-controlled content such as a malicious or compromised web page, causing the browser to access memory that has not been properly initialized. A successful attacker gains code execution under the privileges of the logged-on user, which can enable installation of programs, theft of data, or ransomware staging (ransomware association for this CVE is currently unknown). Anyone still running Internet Explorer is affected; no specific version ranges were provided in the source data, and because IE is a largely retired product, exposure is concentrated in legacy Windows deployments. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-10-06, indicating exploitation in the wild, and EPSS assigns it a 96.9% probability of exploitation within 30 days (100th percentile); no public proof-of-concept is known.
What to do: Inventory your environment for any remaining Internet Explorer use, including legacy Windows systems and MSHTML/IE-mode dependencies, and apply Microsoft security updates addressing this vulnerability on any still-supported systems (the December 2010 cumulative security update MS10-090 resolves it). Where patching is not possible, follow the CISA KEV required action and BOD 22-01 guidance: apply vendor mitigations or discontinue use of Internet Explorer, given the 96.9% EPSS probability of exploitation within 30 days.
| Microsoft Internet Explorer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
- Affected
- Microsoft Internet Explorer
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- Microsoft
- Products
- Internet Explorer