PT-2010-2252 · Microsoft · Internet Explorer
Published
2010-03-31
·
Updated
2021-07-23
·
CVE-2010-0491
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer versions 5.01 SP4 through 6 SP1
Description
A use-after-free issue allows remote attackers to execute arbitrary code by changing properties of an HTML object with an onreadystatechange event handler. The vulnerability exists in the way Internet Explorer accesses an object that has not been correctly initialized or has been deleted. An attacker could exploit this by constructing a specially crafted Web page, potentially allowing remote code execution and gaining the same user rights as the logged-on user. If the user has administrative rights, the attacker could take complete control of the system, install programs, view or modify data, or create new accounts.
Recommendations
For Microsoft Internet Explorer versions 5.01 SP4 through 6 SP1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Explorer