Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-07706

Опубликовано: 14 янв. 2010
Источник: fstec
CVSS3: 8.8
CVSS2: 10
EPSS Критический

Описание

Уязвимость компонента Event Handler браузера Microsoft Internet Explorer связана с использованием памяти после её освобождения. Эксплуатация уязвимости может позволить нарушителю, действующему удалённо, выполнить произвольный код

Вендор

Microsoft Corp

Наименование ПО

Windows XP Service Pack 2
Windows XP Service Pack 3
Windows Server 2003 Service Pack 2
Internet Explorer
Windows 7
Windows Server 2008 R2
Windows Server 2008 Service Pack 2
Windows Server 2008 Gold
Windows Vista Gold SP1
Windows Vista Gold SP2
Windows 2000 SP4

Версия ПО

- (Windows XP Service Pack 2)
- (Windows XP Service Pack 3)
- (Windows Server 2003 Service Pack 2)
8 (Internet Explorer)
7 (Internet Explorer)
6 (Internet Explorer)
- (Windows 7)
6 SP1 (Internet Explorer)
- (Windows Server 2008 R2)
- (Windows Server 2008 Service Pack 2)
- (Windows Server 2008 Gold)
- (Windows Vista Gold SP1)
- (Windows Vista Gold SP2)
- (Windows 2000 SP4)

Тип ПО

Операционная система
Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

Microsoft Corp Windows XP Service Pack 2 -
Microsoft Corp Windows XP Service Pack 3 -
Microsoft Corp Windows Server 2003 Service Pack 2 -
Microsoft Corp Windows 7 -
Microsoft Corp Windows Server 2008 R2 -
Microsoft Corp Windows Server 2008 Service Pack 2 -
Microsoft Corp Windows Server 2008 Gold -
Microsoft Corp Windows Vista Gold SP1 -
Microsoft Corp Windows Vista Gold SP2 -
Microsoft Corp Windows 2000 SP4 -

Уровень опасности уязвимости

Критический уровень опасности (базовая оценка CVSS 2.0 составляет 10)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 8,8)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-002

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Существует в открытом доступе

Информация об устранении

Уязвимость устранена

EPSS

Процентиль: 100%
0.91885
Критический

8.8 High

CVSS3

10 Critical

CVSS2

Связанные уязвимости

CVSS3: 8.8
nvd
больше 16 лет назад

Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object, related to incorrectly initialized memory and improper handling of objects in memory, as exploited in the wild in December 2009 and January 2010 during Operation Aurora, aka "HTML Object Memory Corruption Vulnerability."

CVSS3: 8.8
github
больше 4 лет назад

Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object, related to incorrectly initialized memory and improper handling of objects in memory, as exploited in the wild in December 2009 and January 2010 during Operation Aurora, aka "HTML Object Memory Corruption Vulnerability."

EPSS

Процентиль: 100%
0.91885
Критический

8.8 High

CVSS3

10 Critical

CVSS2