CVE-2010-3962
גבוהה 8.1 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an "invalid flag reference" issue or "Uninitialized Memory Corruption Vulnerability," as exploited in the wild in November 2010.
מדדים
- CVSS 3.1
-
8.1 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 96% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-416
מוצרים מושפעים
microsoft: internet explorer; microsoft: windows server 2003; microsoft: windows xp; microsoft: windows server 2008; microsoft: windows vista; microsoft: windows 7
קישורים
- http://blogs.technet.com/b/msrc/archive/2010/11/02/microsoft-releases-security… Vendor Advisory
- http://secunia.com/advisories/42091 Broken LinkVendor Advisory
- http://www.microsoft.com/technet/security/advisory/2458511.mspx PatchVendor Advisory
- http://www.vupen.com/english/advisories/2010/2880 Broken LinkVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-… PatchVendor Advisory
- http://blogs.technet.com/b/msrc/archive/2010/11/02/microsoft-releases-security… Vendor Advisory
- http://secunia.com/advisories/42091 Broken LinkVendor Advisory
- http://www.microsoft.com/technet/security/advisory/2458511.mspx PatchVendor Advisory
- http://www.vupen.com/english/advisories/2010/2880 Broken LinkVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-… PatchVendor Advisory