← לוח פגיעויות

CVE-2010-3962

גבוהה 8.1 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

תיאור (מקור, אנגלית)

Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an "invalid flag reference" issue or "Uninitialized Memory Corruption Vulnerability," as exploited in the wild in November 2010.

מדדים

CVSS 3.1
8.1 (HIGH) מקור הציון: CNA CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
96% (אחוזון 100) נכון ל-24/7/2026
CWE
CWE-416

מוצרים מושפעים

microsoft: internet explorer; microsoft: windows server 2003; microsoft: windows xp; microsoft: windows server 2008; microsoft: windows vista; microsoft: windows 7

קישורים