KEVIntel
8.8
CVSS
High

CVE-2010-0806

PUBLISHED

Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers...

5928 days faster than CISA KEV

Exploited in the wild PoC available Remote Low complexity
Vendor
Microsoft
Product
Internet Explorer
Published
Mar 10, 2010
EPSS
87.3% · 99% pctl

Automate this intelligence with the Pro API

Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot data — is available programmatically for VM, SOC, and CTI workflows.

Description

Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the wild in March 2010, aka "Uninitialized Memory Corruption Vulnerability."

cisa metasploit microsoft

Weaknesses (CWE)

CVSS scores

CVSS v3.1 8.8 High

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2.0 9.3 High

AV:N/AC:M/Au:N/C:C/I:C/A:C

Exploitation status

Exploited in the wild

Recorded 2010-03-10 22:00:00 UTC · CVE

Proof of concept available

Recorded 2025-04-28 15:02:40 UTC

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CVE First 2010-03-10 22:00 UTC
CISA 2026-06-02 14:00 UTC

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

ms10_018_ie_behaviors

metasploit · Created Unknown

Metasploit module for CVE-2010-0806

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Proof of Concept Exploit Available

  • Detected by Metasploit

  • KEV confirmed by CISA