CVE-2008-4844
HIGH 9.3EPSS 66.5%
Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML DSOs, or (3) Tabular Data Control (TDC) in a crafted HTML or XML document, as demonstrated by nested SPAN or MARQUEE elements, and exploited in the wild in December 2008.
- CVSS v2.0
- 9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C - EPSS
- 66.51% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2008-12-11
- Updated
- 2024-08-07
Proof-of-concept exploits (3)
- https://www.exploit-db.com/exploits/7477
- https://www.exploit-db.com/exploits/7583
- http://www.avertlabs.com/research/blog/index.php/2008/12/09/yet-another-unpatched-drive-b…
Metasploit modules (1)
ExploitDB entries (3)
- https://www.exploit-db.com/exploits/16583
- https://www.exploit-db.com/exploits/7410
- https://www.exploit-db.com/exploits/7403