SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2010-3962

Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability

KEVHIGH 8.1EPSS 96.9%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 27 October 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an "invalid flag reference" issue or "Uninitialized Memory Corruption Vulnerability," as exploited in the wild in November 2010.

CVSS 3.1
8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
96.89% probability · 100th percentile
CISA KEV
Listed 6 October 2025 · due 27 October 2025
Weakness
CWE-416
Affected
microsoft/internet explorer
Source
secure@microsoft.com

CISA notes

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://learn.microsoft.com/en-us/security-updates/SecurityAdvisories/2010/2458511?redirectedfrom=MSDN ; https://nvd.nist.gov/vuln/detail/CVE-2010-3962

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.