PoC Index

CVE-2010-0806

KEVHIGH 9.3EPSS 82.2%

Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the wild in March 2010, aka "Uninitialized Memory Corruption Vulnerability."

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
82.17% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2026-05-20
Published
2010-03-10
Updated
2026-05-21

Metasploit modules (1)

ExploitDB entries (2)

References

Related