CVE-2010-3962

Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to...

Basic Information

CVE State
PUBLISHED
Reserved Date
October 14, 2010
Published Date
November 05, 2010
Last Updated
August 07, 2024
Vendor
Microsoft
Product
Internet Explorer
Description
Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an "invalid flag reference" issue or "Uninitialized Memory Corruption Vulnerability," as exploited in the wild in November 2010.
Tags
metasploit_scanner

CVSS Scores

CVSS v2.0

9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Exploit Status

Exploited in the Wild
Yes (2010-11-05 16:28:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2010-11-05 16:28:00 UTC

Scanner Integrations

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

ms10_090_ie_css_clip

Type: metasploit • Created: Unknown

Metasploit module for CVE-2010-3962

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Metasploit