CVE-2010-0806
Last modified
CVE-2010-0806 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the wild in March 2010, aka "Uninitialized Memory Corruption Vulnerability.". CISA has confirmed active exploitation in the wild. EPSS estimates a 82.05% chance of exploitation in the next 30 days.
Description
Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the wild in March 2010, aka "Uninitialized Memory Corruption Vulnerability."
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Internet Explorer | 5.01 | — |
| Microsoft | Internet Explorer | 6 | Sp1 |
| Microsoft | Internet Explorer | 8 | — |
| Microsoft | Internet Explorer | 7 | — |
References
- http://osvdb.org/62810Broken Link
- http://secunia.com/advisories/38860Vendor Advisory
- http://www.kb.cert.org/vuls/id/744549Patch, US Government Resource
- http://www.microsoft.com/technet/security/advisory/981374.mspxBroken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/38615Broken Link
- http://www.us-cert.gov/cas/techalerts/TA10-068A.htmlUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA10-089A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2010/0567Vendor Advisory
- http://www.vupen.com/english/advisories/2010/0744Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56772Third Party Advisory, VDB Entry
- http://osvdb.org/62810Broken Link
- http://secunia.com/advisories/38860Vendor Advisory
- http://www.kb.cert.org/vuls/id/744549Patch, US Government Resource
- http://www.microsoft.com/technet/security/advisory/981374.mspxBroken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/38615Broken Link
- http://www.us-cert.gov/cas/techalerts/TA10-068A.htmlUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA10-089A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2010/0567Vendor Advisory
- http://www.vupen.com/english/advisories/2010/0744Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56772Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-0806US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2010-0806?
How severe is CVE-2010-0806?
How do I fix CVE-2010-0806?
Are you affected by CVE-2010-0806?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
