CVE-2010-0806 — Microsoft Internet Explorer Use-After-Free Vulnerability
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
- Severity
- critical
- Product
- Microsoft Internet Explorer
- Published
- 2026-05-20
- EPSS
- 0.822
- CISA KEV
- Known exploited
- Ransomware
- Known campaign use
References and validation
- https://github.com/search?q=CVE-2010-0806&type=repositories
- https://nvd.nist.gov/vuln/detail/CVE-2010-0806
Entries are refreshed from CISA KEV and FIRST EPSS. Validate applicability before testing.