CVE-2010-0806 KEV EXPLOIT
8.8
HIGH · CVSS 3.1 · EPSS 82.2% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2026-06-03.
Description
Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the wild in March 2010, aka "Uninitialized Memory Corruption Vulnerability."
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 82.17% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-399 |
| On CISA KEV | yes — remediate by 2026-06-03 |
| Public exploit | yes |
| Published | 2010-03-10 |
| Last modified | 2026-06-16 |
CISA KEV
| Name | Microsoft Internet Explorer Use-After-Free Vulnerability |
|---|---|
| Added | 2026-05-20 |
| Due | 2026-06-03 |
| Vendor / product | Microsoft / Internet Explorer |
| Ransomware use | none reported |
Affected (7)
| Vendor | Product |
|---|---|
| microsoft | internet explorer |
| microsoft | windows 2000 |
| microsoft | windows 7 |
| microsoft | windows server 2003 |
| microsoft | windows server 2008 |
| microsoft | windows vista |
| microsoft | windows xp |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Internet Explorer - DHTML Behaviour Use-After-Free (MS10-018) (Metasploit) | 2010-12-14 |
| exploit-db | Microsoft Internet Explorer - 'iepeers.dll' Use-After-Free (Metasploit) | 2010-03-10 |
References
- http://blogs.technet.com/msrc/archive/2010/03/09/security-advisory-981374-released.aspx
- http://osvdb.org/62810
- http://secunia.com/advisories/38860
- http://www.kb.cert.org/vuls/id/744549
- http://www.microsoft.com/technet/security/advisory/981374.mspx
- http://www.securityfocus.com/bid/38615
- http://www.us-cert.gov/cas/techalerts/TA10-068A.html
- http://www.us-cert.gov/cas/techalerts/TA10-089A.html
- http://www.vupen.com/english/advisories/2010/0567
- http://www.vupen.com/english/advisories/2010/0744
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-018
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56772
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8446
- http://blogs.technet.com/msrc/archive/2010/03/09/security-advisory-981374-released.aspx
- http://osvdb.org/62810
- http://secunia.com/advisories/38860
- http://www.kb.cert.org/vuls/id/744549
- http://www.microsoft.com/technet/security/advisory/981374.mspx
- http://www.securityfocus.com/bid/38615
- http://www.us-cert.gov/cas/techalerts/TA10-068A.html
→ the Explorer · watch your stack · NVD