PT-2010-5197 · Microsoft · Internet Explorer

Jose Antonio Vazquez Gonzalez

·

Published

2010-11-05

·

Updated

2025-10-07

·

CVE-2010-3962

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer versions 6 through 8
Description The issue is related to a use-after-free vulnerability that allows remote attackers to execute arbitrary code. This can be achieved through vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute. An attacker could exploit this by convincing a user to open a malicious document, potentially leading to remote code execution when the document is closed. If successfully exploited, an attacker could gain the same user rights as the logged-on user, and if the user has administrative rights, the attacker could take complete control of the system.
Recommendations For Microsoft Internet Explorer versions 6 through 8, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2010-3962

Affected Products

Internet Explorer