Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object, related to incorrectly initialized memory and improper handling of objects in memory, as exploited in the wild in December 2009 and January 2010 during Operation Aurora, aka "HTML Object Memory Corruption Vulnerability."
Published Jan 15, 2010 ·Due Jun 3, 2026
8.8
HIGHCVSS 3.1
EPSS 91.94%
Description
Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object, related to incorrectly initialized memory and improper handling of objects in memory, as exploited in the wild in December 2009 and January 2010 during Operation Aurora, aka "HTML Object Memory Corruption Vulnerability."
Affected products
No data.
Configuration 1
- 5.0.1
- 6
Running on/with
- n/a
Configuration 2
- 6
Running on/with
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 3
- 7.0
Running on/with
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 4
- 8
Running on/with
- n/a
- n/a
- n/a
- n/a
- r2
- r2
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Date Added
May 20, 2026
Patch Due
Jun 3, 2026
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed May 20, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (19 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 91.94% (0.91939) | 99.82th | v5 (v2026.06.15) |
| Jun 15, 2026 | 91.88% (0.91885) | 99.80th | v5 (v2026.06.15) |
| May 21, 2026 | 88.64% (0.88637) | 99.52th | v4 (v2025.03.14) |
| Dec 4, 2025 | 90.90% (0.90904) | 99.61th | v4 (v2025.03.14) |
| May 15, 2025 | 92.22% (0.92220) | 99.69th | v4 (v2025.03.14) |
| Mar 17, 2025 | 90.98% (0.90983) | 99.62th | v4 (v2025.03.14) |
| Dec 12, 2024 | 95.57% (0.95574) | 99.48th | v3 (v2023.03.01) |
| Jul 15, 2024 | 96.45% (0.96449) | 99.60th | v3 (v2023.03.01) |
| Apr 19, 2024 | 96.67% (0.96672) | 99.63th | v3 (v2023.03.01) |
| Mar 4, 2024 | 96.33% (0.96325) | 99.50th | v3 (v2023.03.01) |
| Feb 16, 2024 | 96.26% (0.96262) | 99.48th | v3 (v2023.03.01) |
| Jan 18, 2024 | 97.34% (0.97344) | 99.88th | v3 (v2023.03.01) |
| Dec 4, 2023 | 97.25% (0.97254) | 99.81th | v3 (v2023.03.01) |
| Oct 21, 2023 | 97.29% (0.97289) | 99.81th | v3 (v2023.03.01) |
| Sep 8, 2023 | 97.18% (0.97178) | 99.72th | v3 (v2023.03.01) |
| Jun 13, 2023 | 97.31% (0.97313) | 99.79th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.33% (0.97329) | 99.76th | v3 (v2023.03.01) |
| Mar 6, 2023 | 89.83% (0.89830) | 99.84th | v2 (v2022.01.01) |
| Feb 4, 2022 | 89.83% (0.89830) | 99.81th | v2 (v2022.01.01) |
References (15)
- http://blogs.technet.com/msrc/archive/2010/01/14/security-advisory-979352.aspx x_refsource_CONFIRMBroken LinkVendor Advisory
- http://news.cnet.com/8301-27080_3-10435232-245.html x_refsource_MISCBroken Link
- http://osvdb.org/61697 vdb-entryx_refsource_OSVDBBroken Link
- http://securitytracker.com/id?1023462 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://support.microsoft.com/kb/979352 vendor-advisoryx_refsource_MSKBPatchVendor Advisory
- http://www.exploit-db.com/exploits/11167 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- http://www.kb.cert.org/vuls/id/492515 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.microsoft.com/technet/security/advisory/979352.mspx x_refsource_CONFIRMBroken LinkPatchVendor Advisory
- http://www.securityfocus.com/bid/37815 vdb-entryx_refsource_BIDBroken LinkExploitThird Party AdvisoryVDB Entry
- http://www.us-cert.gov/cas/techalerts/TA10-055A.html third-party-advisoryx_refsource_CERTBroken LinkThird Party AdvisoryUS Government Resource
- http://www.vupen.com/english/advisories/2010/0135 vdb-entryx_refsource_VUPENBroken Link
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-002 vendor-advisoryx_refsource_MSPatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55642 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6835 vdb-entrysignaturex_refsource_OVALBroken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-0249 government-resourceUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| http://blogs.technet.com/msrc/archive/2010/01/14/security-advisory-979352.aspx | x_refsource_CONFIRMBroken LinkVendor Advisory | |
| http://news.cnet.com/8301-27080_3-10435232-245.html | x_refsource_MISCBroken Link | |
| http://osvdb.org/61697 | vdb-entryx_refsource_OSVDBBroken Link | |
| http://securitytracker.com/id?1023462 | vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry | |
| http://support.microsoft.com/kb/979352 | vendor-advisoryx_refsource_MSKBPatchVendor Advisory | |
| http://www.exploit-db.com/exploits/11167 | exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry | |
| http://www.kb.cert.org/vuls/id/492515 | third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource | |
| http://www.microsoft.com/technet/security/advisory/979352.mspx | x_refsource_CONFIRMBroken LinkPatchVendor Advisory | |
| http://www.securityfocus.com/bid/37815 | vdb-entryx_refsource_BIDBroken LinkExploitThird Party AdvisoryVDB Entry | |
| http://www.us-cert.gov/cas/techalerts/TA10-055A.html | third-party-advisoryx_refsource_CERTBroken LinkThird Party AdvisoryUS Government Resource | |
| http://www.vupen.com/english/advisories/2010/0135 | vdb-entryx_refsource_VUPENBroken Link | |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-002 | vendor-advisoryx_refsource_MSPatchVendor Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/55642 | vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry | |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6835 | vdb-entrysignaturex_refsource_OVALBroken Link | |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-0249 | government-resourceUS Government Resource |
Change history (0)
No recorded changes yet.