CVE-2010-0249

HIGH(8.8)KEVLikely Exploited

Microsoft Internet Explorer Use-After-Free Vulnerability

Description

CVE-2010-0249, addressed by Microsoft bulletin MS10-002, is a high-severity use-after-free vulnerability in Microsoft Internet Explorer. By accessing a pointer associated with a deleted object, a crafted web page can corrupt memory and let a remote attacker execute arbitrary code in the context of the user browsing the page. This is the "HTML Object Memory Corruption" flaw famously exploited during Operation Aurora, the targeted intrusion campaign against Google and other companies in late 2009 and early 2010. With a CVSS score of 8.8, an EPSS score of 88.7% (99.5th percentile), and a CISA KEV listing, CVE-2010-0249 remains dangerous — and because Internet Explorer is end-of-life, the recommended action is to discontinue its use.

KEV Information

Vendor
Microsoft
Product
Internet Explorer
Date Added
May 20, 2026
Due Date
June 3, 2026
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
microsoftinternet explorer5.0.1; 6; 7.0; 8

Multiple CVSS Assessments

Source: [email protected](Primary)
8.8
HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
8.8
HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-416: Use After Free

In Internet Explorer, the use-after-free occurs when the browser accesses a pointer to an object that has already been deleted (related to incorrectly initialized memory and improper handling of objects in memory). A crafted HTML page can manipulate object lifetimes so that the freed memory is reused under attacker control, leading to memory corruption and arbitrary code execution.

Learn more: CWE-416 — Use After Free

Impact Analysis

CVE-2010-0249 carries a CVSS 3.1 score of 8.8 (HIGH). It is remotely exploitable over the network with low attack complexity and requires no privileges, but it does require user interaction — the victim must visit a malicious or compromised web page — and on success it fully compromises the confidentiality, integrity, and availability of the system in the user's context. This was the vulnerability at the heart of Operation Aurora, a sophisticated targeted campaign that breached Google and numerous other organizations, demonstrating how a single browser use-after-free can serve as the initial foothold for high-impact intrusions. The EPSS score of 88.7% (99.5th percentile) reflects near-certain exploitation activity, and because Internet Explorer is end-of-life, affected systems cannot rely on future patches and should migrate to a supported browser.

Exploit Maturity

CVE-2010-0249 has a mature and well-documented exploit landscape. Public exploit code is available via Exploit-DB, and the flaw was weaponized in the targeted Operation Aurora campaign against Google and other companies in December 2009 and January 2010. CISA confirms active exploitation through its KEV listing, and the EPSS score of 88.7% (99.5th percentile) indicates near-certain exploitation activity. Given the publicly available exploit, the historical use in a high-profile campaign, and the end-of-life status of Internet Explorer, any environment still running IE is at acute risk and should discontinue its use.

Remediation

  1. Discontinue use of Internet Explorer as advised by CISA: the impacted product is end-of-life/end-of-service, so migrate to a supported, actively maintained browser rather than relying on the legacy component.
  2. Where IE must temporarily remain, apply the MS10-002 update (CISA KEV deadline 2026-06-03) on any supported underlying Windows version that can still receive it.
  3. As an interim mitigation, enforce Data Execution Prevention (DEP) for Internet Explorer and restrict browsing to trusted sites, since exploitation requires the victim to load a malicious page.
  4. Block access to untrusted web content at the proxy/gateway and deploy endpoint protection that detects use-after-free exploitation and anomalous browser child processes.
  5. As long-term hardening against use-after-free flaws, remove or disable legacy browsers, standardize on a modern browser with strong memory-safety mitigations, and segment any systems that must run unsupported software.

Technical Details

CVE-2010-0249 is a use-after-free vulnerability (CWE-416) in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 across Windows 2000 SP4, XP SP2/SP3, Server 2003 SP2, Vista, Server 2008, and Windows 7. The browser accesses a pointer associated with a deleted object — a condition related to incorrectly initialized memory and improper handling of objects in memory — allowing a crafted HTML page to reclaim the freed memory with attacker-controlled data and corrupt memory to achieve code execution. The CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) reflects a network-deliverable, low-complexity attack requiring the victim to view a malicious page, after which the system is fully compromised in the user's context. The flaw was exploited in the wild during Operation Aurora in December 2009 and January 2010.

Frequently Asked Questions

Is CVE-2010-0249 being actively exploited?

Yes. CVE-2010-0249 is on the CISA Known Exploited Vulnerabilities catalog with an EPSS score of 88.7% (99.5th percentile), and it was exploited in the targeted Operation Aurora campaign in 2009–2010. Public exploit code is available, so unpatched systems face near-certain exploitation.

What products are affected by CVE-2010-0249?

The vulnerability affects Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4, Windows XP SP2/SP3, Windows Server 2003 SP2, Windows Vista, Windows Server 2008, and Windows 7. Internet Explorer is end-of-life and should be discontinued.

How do I fix CVE-2010-0249?

Discontinue use of Internet Explorer and migrate to a supported browser. Where IE temporarily remains and the underlying Windows version still receives updates, apply the Microsoft MS10-002 security update and enforce DEP as an interim measure.

How severe is CVE-2010-0249?

CVE-2010-0249 is rated HIGH with a CVSS 3.1 score of 8.8. A crafted web page can trigger a use-after-free leading to remote code execution in the user's context, and the flaw is historically notable as the entry point for the Operation Aurora intrusions.

CVSS Score

8.8
HIGH(8.8)

EPSS Score

EPSS Score91.88%
EPSS Percentile99.8%

Dates

PublishedJanuary 15, 2010
Last ModifiedJune 16, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.