Junglewise Threat Intelligence

CVE-2010-0249: Microsoft Internet Explorer use-after-free in HTML object handling

CVE-2010-0249 · Severity: critical · CVSS 9.3 · Exploited in the wild · Published 2026-06-03

Technologies: Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

Internet Explorer is a web browser used to access the internet and internal web applications. A critical vulnerability allows an attacker to take complete control of a user's computer if they visit a malicious website. This flaw was famously used in the 'Operation Aurora' attacks to breach major technology companies, potentially leading to the theft of intellectual property and unauthorized access to sensitive corporate data.

Technical details

A use-after-free vulnerability exists in Microsoft Internet Explorer versions 6, 7, and 8 due to improper handling of objects in memory and incorrectly initialized memory. By accessing a pointer associated with a deleted HTML object, a remote attacker can trigger memory corruption. This is exploitable via a network vector if a user is enticed to view a malicious webpage (User Interaction required). Successful exploitation allows for arbitrary code execution in the context of the current user. This vulnerability was notably utilized in the 'Operation Aurora' targeted attacks. Microsoft has released security bulletin MS10-002 to address this issue.

Affected products

  • Microsoft Internet Explorer 6, 6 SP1, 7, 8

Timeline

  • 2009-12: exploited: Exploited in the wild during Operation Aurora
  • 2010-01-21: patched: Microsoft released MS10-002 to address the issue
  • 2026-06-03: disclosed: NVD advisory publication date

Related threats