CVE-2010-3962
Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 27 October 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an "invalid flag reference" issue or "Uninitialized Memory Corruption Vulnerability," as exploited in the wild in November 2010.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 96.89% probability · 100th percentile
- CISA KEV
- Listed 6 October 2025 · due 27 October 2025
- Weakness
- CWE-416
- Affected
- microsoft/internet explorer
- Source
- secure@microsoft.com
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://learn.microsoft.com/en-us/security-updates/SecurityAdvisories/2010/2458511?redirectedfrom=MSDN ; https://nvd.nist.gov/vuln/detail/CVE-2010-3962
References
- http://blogs.technet.com/b/msrc/archive/2010/11/02/microsoft-releases-security-advisory-2458511.aspxVendor Advisory
- http://secunia.com/advisories/42091Broken Link, Vendor Advisory
- http://www.exploit-db.com/exploits/15418Third Party Advisory, VDB Entry
- http://www.exploit-db.com/exploits/15421Third Party Advisory, VDB Entry
- http://www.kb.cert.org/vuls/id/899748Third Party Advisory, US Government Resource
- http://www.microsoft.com/technet/security/advisory/2458511.mspxPatch, Vendor Advisory
- http://www.securityfocus.com/bid/44536Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1024676Broken Link, Third Party Advisory, VDB Entry
- http://www.symantec.com/connect/blogs/new-ie-0-day-used-targeted-attacksNot Applicable
- http://www.us-cert.gov/cas/techalerts/TA10-348A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2010/2880Broken Link, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-090Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/62962Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12279Tool Signature
- http://blogs.technet.com/b/msrc/archive/2010/11/02/microsoft-releases-security-advisory-2458511.aspxVendor Advisory
- http://secunia.com/advisories/42091Broken Link, Vendor Advisory
- http://www.exploit-db.com/exploits/15418Third Party Advisory, VDB Entry
- http://www.exploit-db.com/exploits/15421Third Party Advisory, VDB Entry
- http://www.kb.cert.org/vuls/id/899748Third Party Advisory, US Government Resource
- http://www.microsoft.com/technet/security/advisory/2458511.mspxPatch, Vendor Advisory
- http://www.securityfocus.com/bid/44536Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1024676Broken Link, Third Party Advisory, VDB Entry
- http://www.symantec.com/connect/blogs/new-ie-0-day-used-targeted-attacksNot Applicable
- http://www.us-cert.gov/cas/techalerts/TA10-348A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2010/2880Broken Link, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-090Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/62962Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12279Tool Signature
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-3962US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.