PoC Index

CVE-2010-0248

HIGH 9.3EPSS 53.1%

Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Object Memory Corruption Vulnerability."

CVSS v3.1
8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
53.09% chance of exploitation in the next 30 days, 99th percentile
Published
2010-01-22
Updated
2024-10-21

Metasploit modules (1)

ExploitDB entries (1)

References

Related