CVE-2010-0249Active Exploitation(microsoft / internet_explorer)

MEDIUMCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch microsoft internet_explorer systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object, related to incorrectly initialized memory and improper handling of objects in memory, as exploited in the wild in December 2009 and January 2010 during Operation Aurora, aka "HTML Object Memory Corruption Vulnerability."

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-06-03. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • internet_explorer
  • windows_2000
  • windows_7
  • windows_server_2003

Threat summary

  • Active exploitation appears in 7 classified signals
  • Patch or workaround signal is available
  • 11 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 7 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • General: 2 classified signals
  • Peaked 2d ago at 4 mentions (2026-05-20); latest day: 3
  • 11 total mentions across 3 days

Affected systems

Vendors
Products
internet_explorerwindows_2000windows_7windows_server_2003windows_server_2008windows_vistawindows_xp

6 versions affected across 7 products

Deep dive

Activity timeline11 mentions / 3d
01234Mentions · 2026-05-20: 4Mentions · 2026-05-21: 4Mentions · 2026-06-10: 3Active Exploitation · 2026-05-20: 1Active Exploitation · 2026-05-21: 3Active Exploitation · 2026-06-10: 3Patch / Workaround · 2026-05-20: 1Patch / Workaround · 2026-05-21: 2Technical Details · 2026-05-20: 2Technical Details · 2026-05-21: 2Technical Details · 2026-06-10: 105-2005-2106-10
Signal classification4 categories
Active Exploitation
654.5%
General
218.2%
Patch
218.2%
Disclosure
19.1%
Referenced assets18 URLs
Classification over time
DateTotalLabels
2026-05-204
Active Exploitation1Disclosure1General2
2026-05-214
Active Exploitation2Patch2
2026-06-103
Active Exploitation3
Full discourse11 posts
  • piyokango@piyokango
    Patch

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(5/20追加) 🛡️No.1594 CVE-2008-4250 Microsoft Windows Buffer Overflow Vulnerability ==================================== ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / CISA-ADP ・種別:バッファエラー (CWE-119) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Microsoft Windows の Server service において、細工された RPC リクエストによりパス正規化処理中にオーバーフローが発生し、リモートから任意のコード実行をされる恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅攻撃前提条件 ・影響を受ける Windows Server service が稼働していること。 ・攻撃者が対象へネットワーク越しに到達可能であること。 ・認証は不要。 ✅悪用時影響 ・リモートで任意のコードを実行される ・影響を受けるシステムを完全に制御される ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2008-4250 https://learn.microsoft.com/ja-jp/security-updates/securitybulletins/2008/ms08-067 🛡️No.1595 CVE-2009-1537 Microsoft DirectX NULL Byte Overwrite Vulnerability =================================== ✅概要 ・深刻度:重要 8.8 (CVSS Base) / CISA-ADP ・種別:NULL バイトまたは NULL キャラクタの不適切な無害化 (CWE-158) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Microsoft DirectX の DirectShow に含まれる QuickTime Movie Parser Filter において、細工された QuickTime メディアファイルにより任意のコード実行をされる恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ✅攻撃前提条件 ・影響を受ける DirectX/Windows 環境が稼働していること。 ・攻撃者が細工された QuickTime メディアファイルを対象へ到達させること。 ・利用者が当該ファイルを処理すること。 ✅悪用時影響 ・リモートで任意のコードを実行される ・細工されたメディアファイルの処理によりシステムが侵害される ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み。Microsoft は、当時このエクスプロイトコードを使用した限定的なアクティブ攻撃を認識していると報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2009-1537 https://learn.microsoft.com/ja-jp/security-updates/securityadvisories/2009/971778 🛡️No.1596 CVE-2009-3459 Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability ==================================== ✅概要 ・深刻度:重要 8.8 (CVSS Base) / CISA-ADP ・種別:ヒープベースのバッファオーバーフロー (CWE-122) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Adobe Reader および Acrobat において、細工された PDF の処理によりメモリ破損が発生し、リモートで任意コードを実行される恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ✅攻撃前提条件 ・影響を受ける Adobe Reader または Acrobat が稼働していること。 ・攻撃者が細工された PDF ファイルを対象へ到達させること。 ・利用者が当該 PDF を開くこと。 ✅悪用時影響 ・リモートで任意のコードを実行される ・PDF 処理時のメモリ破損によりシステムを侵害される✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2009-3459 http://blogs.adobe.com/psirt/2009/10/adobe_reader_and_acrobat_issue_1.html 🛡️No.1597 CVE-2010-0249 Microsoft Internet Explorer Use-After-Free Vulnerability ✅概要 ・深刻度:重要 8.8 (CVSS Base) / NVD ・種別:解放済みメモリの使用 (CWE-416) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Microsoft Internet Explorer 6/7/8 における use-after-free の脆弱性が存在。削除済みオブジェクトに関連するポインタへアクセスさせることで、リモートで任意コードを実行される恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ✅攻撃前提条件 ・影響を受ける Internet Explorer が稼働していること。 ・攻撃者が細工された Web ページへ利用者を誘導できること。 ・利用者が当該 Web ページを表示すること。 ✅悪用時影響 ・リモートで任意のコードを実行される ・メモリ内オブジェクトの不適切な取り扱いによりブラウザ経由で侵害される ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2010-0249 https://learn.microsoft.com/ja-jp/security-updates/securitybulletins/2010/ms10-002 🛡️No.1598 CVE-2010-0806 Microsoft Internet Explorer Use-After-Free Vulnerability ✅概要 ・深刻度:重要 8.8 (CVSS Base) / CISA-ADP ・種別:解放済みメモリの使用 (CWE-416) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Internet Explorer の Peer Objects component(iepeers.dll)における use-after-free の脆弱性が存在。オブジェクト削除後の無効ポインタ参照により、リモートで任意コードを実行される恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ✅攻撃前提条件 ・影響を受ける Internet Explorer が稼働していること。 ・攻撃者が細工された Web ページへ利用者を誘導できること。 (Microsoft Learn) ・利用者が当該 Web ページを表示すること。 ✅悪用時影響 ・リモートで任意のコードを実行される ・オブジェクト解放後の不正参照によりブラウザ経由で侵害される ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2010-0806 https://learn.microsoft.com/ja-jp/security-updates/securitybulletins/2010/ms10-018 🛡️No.1599 CVE-2026-41091 Microsoft Defender Elevation of Privilege Vulnerability =================================== ✅概要 ・深刻度:重要 7.8 (CVSS Base) / Microsoft Corporation ・種別:リンク解釈の問題 (CWE-59) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Microsoft Defender における link following の脆弱性が存在。認証済みの攻撃者により、ローカル上で権限昇格される恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:高 ✅攻撃前提条件 ・影響を受ける Microsoft Malware Protection Engine が稼働していること。 ・攻撃者がローカルで認証済み権限を有していること。 ・ローカルで悪用可能な環境であること。 ✅悪用時影響 ・ローカルで権限昇格される ・機密性、完全性、可用性に高い影響が生じる ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-41091 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091 🛡️No.1600 CVE-2026-45498 Microsoft Defender Denial of Service Vulnerability ✅概要 ・深刻度:重要 7.5 (CVSS Base) / NVD ・種別:リソースの枯渇 (CWE-400) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Microsoft Defender におけるサービス運用妨害の脆弱性が存在。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅攻撃前提条件 ・影響を受ける Microsoft Defender Antimalware Platform が稼働していること。 ・NVD 採点上、攻撃者がネットワーク越しに到達可能であること。 ・認証は不要。 ✅悪用時影響 ・サービス運用妨害により可用性へ高い影響が生じる ・Microsoft Defender の動作停止または機能阻害につながる ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-45498 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45498 https://www.cisa.gov/news-events/alerts/2026/05/20/cisa-adds-seven-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    The post lists seven CISA-added CVEs, providing severity, technical details, and patch information, with an active exploit confirmed for CVE‑2009‑1537.

    020626.3K
    43.9K followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに7件追加。10年以上前のAcrobatのCVE-2009-3459及びMSのCVE-2008-4250、CVE-2009-1537、CVE-2010-0249、CVE-2010-0806、並びに多分RedSunのCVE-2026-41091とUnDefendのCVE-2026-45498。 https://www.cisa.gov/news-events/alerts/2026/05/20/cisa-adds-seven-known-exploited-vulnerabilities-catalog

    Post summary

    CISA announced the addition of seven historical CVEs to its catalog of known exploited vulnerabilities, listing only the CVE identifiers with no technical, exploit, or mitigation details.

    101301.5K
    7.5K followersView on X
  • Trio Soft inc@triosoftinc
    Active Exploitation

    5 of CISA's 7 new KEV entries date to 2008-2010. CVE-2008-4250 (Conficker). CVE-2010-0249 (Aurora). Two 2026 Microsoft Defender CVEs join them. Your oldest unpatched endpoints are the easiest entry points. #EndpointSecurity #ITAdmin #CyberSecurity #CISA https://t.co/tqCii3yOiF

    Post summary

    The tweet lists five CISA KEV entries, including older CVEs, underscoring that these vulnerabilities are actively exploited and that unpatched endpoints are particularly vulnerable.

    1002045
    21 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Vendor. CVE-2010-0249 added to CISA KEV: Microsoft Internet Explorer Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object.

    Post summary

    The post notes that CVE‑2010‑0249, a use‑after‑free in Internet Explorer, is listed in CISA KEV, confirming it has been exploited in the wild, though no PoC or patch details are provided.

    1000031
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2010-0249. CVE-2010-0249 added to CISA KEV: Microsoft Internet Explorer

    Post summary

    CVE-2010-0249, a Microsoft Internet Explorer flaw, has been added to the CISA Known Exploited Vulnerabilities list, indicating it is a known, high‑impact vulnerability with no publicly available PoC, exploit tool, or patch information in the statement.

    1000024
    258 followersView on X
  • Trio Soft inc@triosoftinc
    Patch

    👉 CVE-2008-4250 has been patchable since October 2008. CVE-2010-0249 since January 2010. Both still active in 2026 because fleet patch coverage is the part nobody audits. Trio MDM shows you exactly where the gap is.

    Post summary

    The tweet notes that these legacy CVEs remain unpatched in 2026 due to poor patch coverage and promotes Trio MDM for detecting coverage gaps.

    0001032
    21 followersView on X
  • ThreatLevel@ThreatLevelAI
    Active Exploitation

    🚨 Remote Code Execution in Microsoft Internet Explorer added to the CISA Known Exploited Vulnerabilities catalog (CVE-2010-0249). Active exploitation confirmed. Patch immediately. More details 👇 https://t.co/DKufk5r1dm

    Post summary

    The tweet alerts that CVE‑2010‑0249, a Remote Code Execution flaw in Internet Explorer, is being actively exploited in the wild and urges immediate patching, with a link for additional details.

    1000046
    7 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://lyrie.ai/research/research/active-exploit-cve-2010-0249-internet-explorer #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The linked page reportedly describes active exploitation of CVE‑2010‑0249 in Internet Explorer, but the provided excerpt contains no technical details or PoC.

    0000021
    258 followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISAが既知の悪用された脆弱性7件をカタログに追加 CISA Adds Seven Known Exploited Vulnerabilities to Catalog #CISA (May 20) CVE-2008-4250 Microsoft Windows バッファオーバーフローの脆弱性 CVE-2009-1537 Microsoft DirectXのNULLバイト上書きの脆弱性 CVE-2009-3459 Adobe AcrobatおよびReaderのヒープベースのバッファオーバーフローの脆弱性 CVE-2010-0249 Microsoft Internet ExplorerのUse-After-Free脆弱性 CVE-2010-0806 Microsoft Internet ExplorerのUse-After-Free脆弱性 CVE-2026-41091 Microsoft Defenderの特権昇格の脆弱性 CVE-2026-45498 Microsoft Defenderのサービス拒否攻撃の脆弱性 https://www.cisa.gov/news-events/alerts/2026/05/20/cisa-adds-seven-known-exploited-vulnerabilities-catalog

    Post summary

    CISA announced that seven CVEs, previously known to be exploited, have been added to its catalog, confirming their active exploitation status but without providing PoC or patch information.

    00000256
    4.8K followersView on X
  • Israel@f1tym1
    General

    CVE-2010-0249 | Microsoft Internet Explorer 6/6 SP1/7/8 Event resource management (MSRC/ARC / VU#492515) https://ift.tt/Q1c7v6b A vulnerability was found in Microsoft Internet Explorer 6/6 SP1/7/8 and classified as very critical. This affects an unknown function of the compone…

    Post summary

    The text is a brief notice of the CVE’s existence and severity, without providing technical details, PoC, or patch information.

    0000063
    974 followersView on X
  • DailyCVE@dailycve
    General

    🔴 Internet Explorer, Use-after-free, #CVE-2010-0249 (Critical) https://dailycve.com/internet-explorer-use-after-free-cve-2010-0249-critical/

    Post summary

    A short notice referencing a critical internet explorer use‑after‑free vulnerability with a link to a dailyCVE page, without additional details on exploitation or mitigation.

    0000044
    206 followersView on X
CPE platform detail19 entries

19 of 19 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftinternet_explorer5.0.1--
Appmicrosoftinternet_explorer6--
Appmicrosoftinternet_explorer6--
Appmicrosoftinternet_explorer7.0--
Appmicrosoftinternet_explorer8--
OSmicrosoftwindows_2000---
OSmicrosoftwindows_7---
OSmicrosoftwindows_server_2003--itanium
OSmicrosoftwindows_server_2003--x64
OSmicrosoftwindows_server_2008---
OSmicrosoftwindows_server_2008---
OSmicrosoftwindows_server_2008r2-itanium
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_vista--x64
OSmicrosoftwindows_vista--x64
OSmicrosoftwindows_vista--x64
OSmicrosoftwindows_xp---
OSmicrosoftwindows_xp--x64
OSmicrosoftwindows_xp---

Explore more