CVE-2008-4844

High PUBLISHED

Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1,...

Vendor: Microsoft Product: Internet Explorer

Not yet in CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
9.3 High EPSS 66.5%

At a Glance

Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML DSOs, or (3) Tabular Data Control (TDC) in a crafted HTML or XML document, as demonstrated by nested SPAN or MARQUEE elements, and exploited in the wild in December 2008.

metasploit
CVE Published
Dec 11, 2008
Exploitation Reported
Dec 11, 2008
CVSS
9.3 High
EPSS
66.5%
Remote Unauthenticated

CVE References

  • HPSBST02397 marc.info · Vendor Advisory http://marc.info/?l=bugtraq&m=123015308222620&w=2
  • MS08-078 docs.microsoft.com · Vendor Advisory https://docs.microsoft.com/en-us/security-updates/securitybulletins/2...
  • TA08-352A us-cert.gov · Third-Party Advisory http://www.us-cert.gov/cas/techalerts/TA08-352A.html
  • VU#493881 kb.cert.org · Third-Party Advisory http://www.kb.cert.org/vuls/id/493881
  • TA08-344A us-cert.gov · Third-Party Advisory http://www.us-cert.gov/cas/techalerts/TA08-344A.html
Show 16 more references