CVE-2010-0806

EXPLOITED IN THE WILD

Microsoft Internet Explorer <7 - Use After Free

Title source: llm

Description

Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the wild in March 2010, aka "Uninitialized Memory Corruption Vulnerability."

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16590
exploitdb WORKING POC VERIFIED
by Trancer · rubyremotewindows
https://www.exploit-db.com/exploits/11683
metasploit WORKING POC GOOD
by unknown · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/ms10_018_ie_behaviors.rb

Scores

EPSS 0.8948
EPSS Percentile 99.6%

Details

VulnCheck KEV 2010-03-10
InTheWild.io 2021-07-23
CWE
CWE-399
Status published
Products (8)
microsoft/internet_explorer 7
microsoft/internet_explorer 6
microsoft/windows_2000
microsoft/windows_2003_server (2 CPE variants)
microsoft/windows_server_2003
microsoft/windows_server_2008 (6 CPE variants)
microsoft/windows_vista (4 CPE variants)
microsoft/windows_xp (3 CPE variants)
Published Mar 10, 2010
Tracked Since Feb 18, 2026