CVE-2009-2764

Microsoft Internet Explorer 8.0.7100.0 - DoS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-2764. PoCs published by schnuddelbuddel.

AI-analyzed exploit summary This exploit leverages a vulnerability in Internet Explorer 8.0.7100.0 on Windows 7 x64 RC, where a malformed HTML document with a non-existent script source causes a crash or potential code execution due to improper handling of the script tag.

Description

Microsoft Internet Explorer 8.0.7100.0 on Windows 7 RC on the x64 platform allows remote attackers to cause a denial of service (application crash) via a certain DIV element in conjunction with SCRIPT elements that have empty contents and no reference to a valid external script location.

Exploits (1)

exploitdb WORKING POC VERIFIED
by schnuddelbuddel · htmldoswindows
https://www.exploit-db.com/exploits/9362

This exploit leverages a vulnerability in Internet Explorer 8.0.7100.0 on Windows 7 x64 RC, where a malformed HTML document with a non-existent script source causes a crash or potential code execution due to improper handling of the script tag.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Internet Explorer 8.0.7100.0 on Windows 7 x64 RC
No auth needed
Prerequisites: Victim must visit a malicious webpage using a vulnerable version of Internet Explorer
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/35941
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/9362

Scores

EPSS 0.1100
EPSS Percentile 95.3%

Details

Status published
Products (2)
microsoft/internet_explorer 8.0.7100.0
microsoft/windows_7
Published Aug 14, 2009
Tracked Since Feb 18, 2026