PT-2010-2252 · Microsoft · Internet Explorer

Published

2010-03-31

·

Updated

2021-07-23

·

CVE-2010-0491

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer versions 5.01 SP4 through 6 SP1
Description A use-after-free issue allows remote attackers to execute arbitrary code by changing properties of an HTML object with an onreadystatechange event handler. The vulnerability exists in the way Internet Explorer accesses an object that has not been correctly initialized or has been deleted. An attacker could exploit this by constructing a specially crafted Web page, potentially allowing remote code execution and gaining the same user rights as the logged-on user. If the user has administrative rights, the attacker could take complete control of the system, install programs, view or modify data, or create new accounts.
Recommendations For Microsoft Internet Explorer versions 5.01 SP4 through 6 SP1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-0491

Affected Products

Internet Explorer