Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
HighCISA KEVExploited in the wildPublic exploit

Microsoft Internet Explorer HTML Object Memory Corruption Use-After-Free

IdentifiersCVE-2010-0249CWE-416· Use After Free

CVE-2010-0249 is a use-after-free memory corruption vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8. A deleted object can still be referenced through a stale pointer due to improper handling of objects in memory and incorrectly initialized memory. Microsoft and related reporting describe the issue as an invalid pointer access after an object has been deleted, also referred to as the "HTML Object Memory Corruption Vulnerability." Successful exploitation can be triggered by malicious web content, including a specially crafted HTML page, and some advisories also note a Microsoft Office document as a delivery vector for the malicious HTML content. The flaw was exploited in the wild in late 2009 and early 2010, including during Operation Aurora.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows remote arbitrary code execution in the security context of the current user. If the user has administrative privileges, the attacker may fully compromise the affected system. The vulnerability can also cause a denial-of-service condition through browser or process crash if exploitation does not achieve reliable code execution.

Mitigation

If you can’t patch tonight, do this now.

Until patches or platform replacement are completed, enable Data Execution Prevention (DEP) for Internet Explorer 6 and 7, set the Internet zone security level to High, disable Active Scripting, and restrict or disable ActiveX controls. For the Office-based delivery vector, disable ActiveX controls in Microsoft Office. More broadly, reduce exposure by preventing use of legacy Internet Explorer versions, limiting browsing from privileged accounts, and restricting access to untrusted web content.

Remediation

Patch, then assume compromise.

Apply Microsoft's security update for this issue, specifically the fix released in Microsoft Security Bulletin MS10-002 / Security Advisory 979352. Because the affected Internet Explorer versions and several affected Windows platforms are legacy or end-of-life, organizations should also retire or replace unsupported systems and discontinue use where vendor-supported remediation is no longer practical.
PUBLIC EXPLOITS

Exploits

No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.

VALID 0 / 1 TOTALView more in app

All candidate exploits were filtered out by Mallory's validation.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
Microsoft CorporationInternet Explorerapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures1

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity11

Community discussion across Reddit, Mastodon, and other social sources.