Known vulnerability record
CVE-2010-0249
Microsoft Internet Explorer Use-After-Free Vulnerability
Summary
Microsoft Internet Explorer Use-After-Free Vulnerability
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Signals
Keep the signals separate
CVSS severityhighScore 8.8 · source CISA-ADP
EPSS probability91.9%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-05-20
Ransomware useunknownPreserved as known / unknown, not a truthy default
Timeline
Dates and provenance
- CVE published
- 2010-01-15
- CVE modified
- 2026-05-21
- KEV date added
- 2026-05-20
- Dataset fetched
- 2026-08-21T03:55:08.035Z
Sources
Original records
- https://www.cve.org/CVERecord?id=CVE-2010-0249 ↗
- https://nvd.nist.gov/vuln/detail/CVE-2010-0249 ↗
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-0249 ↗
Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.