CVE-2009-0076

Microsoft Internet Explorer 7 - RCE

Title source: llm

Description

Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the zoom style directive in conjunction with unspecified other directives in a malformed Cascading Style Sheets (CSS) stylesheet in a crafted HTML document, aka "CSS Memory Corruption Vulnerability."

Exploits (4)

exploitdb WORKING POC VERIFIED
by webDEViL · htmlremotewindows
https://www.exploit-db.com/exploits/8082
exploitdb WORKING POC VERIFIED
by David Kennedy (ReL1K) · pythonremotewindows
https://www.exploit-db.com/exploits/8080
exploitdb WORKING POC VERIFIED
by Ahmed Obied · pythonremotewindows
https://www.exploit-db.com/exploits/8152
exploitdb WORKING POC VERIFIED
by Abysssec · htmlremotewindows
https://www.exploit-db.com/exploits/8079

Scores

EPSS 0.5848
EPSS Percentile 98.2%

Classification

CWE
CWE-399
Status draft

Affected Products (1)

microsoft/internet_explorer

Timeline

Published Feb 10, 2009
Tracked Since Feb 18, 2026