KEVIntel
9.3
CVSS
High

CVE-2008-4844

PUBLISHED

Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1,...

Not yet in CISA KEV

Exploited in the wild PoC available Remote
Vendor
Microsoft
Product
Internet Explorer
Published
Dec 11, 2008
EPSS

Automate This Intelligence with the Pro API

Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot data — is available programmatically for VM, SOC, and CTI workflows.

Description

Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML DSOs, or (3) Tabular Data Control (TDC) in a crafted HTML or XML document, as demonstrated by nested SPAN or MARQUEE elements, and exploited in the wild in December 2008.

metasploit

CVSS Scores

CVSS v2.0 9.3 High

AV:N/AC:M/Au:N/C:C/I:C/A:C

Exploitation Status

Exploited in the wild

Recorded 2008-12-11 15:00:00 UTC · CVE

Proof of concept available

Recorded 2025-04-28 15:02:40 UTC

Known Exploited Vulnerability Sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CVE First 2008-12-11 15:00 UTC

Potential Proof of Concepts

These PoCs are unverified and could contain malware. Use at your own risk.

ms08_078_xml_corruption

metasploit · Created Unknown

Metasploit module for CVE-2008-4844

Timeline

  • Detected by Metasploit

  • Proof of Concept Exploit Available

  • Added to KEVIntel

  • CVE Published to Public

  • CVE ID Reserved