CVE-2009-0076

Microsoft Internet Explorer 7 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2009-0076. PoCs published by Ahmed Obied, David Kennedy (ReL1K), Abysssec.

AI-analyzed exploit summary This exploit targets CVE-2009-0076, a use-after-free vulnerability in Internet Explorer 7, by spraying the heap with shellcode and triggering the bug via JavaScript. It delivers a calc.exe payload via a malicious HTTP server.

Description

Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the zoom style directive in conjunction with unspecified other directives in a malformed Cascading Style Sheets (CSS) stylesheet in a crafted HTML document, aka "CSS Memory Corruption Vulnerability."

Exploits (4)

exploitdb WORKING POC VERIFIED
by Ahmed Obied · pythonremotewindows
https://www.exploit-db.com/exploits/8152

This exploit targets CVE-2009-0076, a use-after-free vulnerability in Internet Explorer 7, by spraying the heap with shellcode and triggering the bug via JavaScript. It delivers a calc.exe payload via a malicious HTTP server.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Internet Explorer 7.0.5730.11 on Windows XP SP2
No auth needed
Prerequisites: Victim must visit the malicious HTTP server · Target must be using Internet Explorer 7
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by David Kennedy (ReL1K) · pythonremotewindows
https://www.exploit-db.com/exploits/8080

This exploit targets a memory corruption vulnerability in Microsoft Internet Explorer 7 (CVE-2009-0076) by serving a malicious HTML page with JavaScript that triggers a buffer overflow, leading to remote code execution via a bind shell on port 5500.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Internet Explorer 7
No auth needed
Prerequisites: Victim must visit the malicious HTTP server on port 80 · Internet Explorer 7 must be vulnerable (unpatched)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Abysssec · htmlremotewindows
https://www.exploit-db.com/exploits/8079

This exploit targets a memory corruption vulnerability in Internet Explorer 7 (CVE-2009-0076) via JavaScript heap spraying. It uses a bind shell shellcode to achieve remote code execution on vulnerable systems.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Internet Explorer 7
No auth needed
Prerequisites: Victim must visit a malicious webpage using Internet Explorer 7
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by webDEViL · htmlremotewindows
https://www.exploit-db.com/exploits/8082

This is a heap spray exploit targeting CVE-2009-0075, a vulnerability in Microsoft Internet Explorer's handling of HTML objects. The exploit uses JavaScript to spray the heap with shellcode and trigger the vulnerability via the 'click' method on a cloned 'tbody' element, leading to arbitrary code execution (spawning calc.exe).

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Internet Explorer (tested on Windows Server 2003 SP2)
No auth needed
Prerequisites: Victim must visit a malicious webpage using a vulnerable version of Internet Explorer
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6081
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA09-041A.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0389
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-09-012/

Scores

EPSS 0.3354
EPSS Percentile 98.2%

Details

CWE
CWE-399
Status published
Products (1)
microsoft/internet_explorer 7
Published Feb 10, 2009
Tracked Since Feb 18, 2026