Junglewise Threat Intelligence

CVE-2010-0806: Microsoft Internet Explorer use-after-free in Peer Objects

CVE-2010-0806 · Severity: critical · CVSS 9.3 · Exploited in the wild · Published 2026-05-20

Technologies: Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

Microsoft Internet Explorer contains a critical vulnerability in how it handles memory for certain web objects. An attacker could exploit this by tricking a user into visiting a malicious website, allowing the attacker to take full control of the user's computer. This flaw was actively used by attackers in the wild to install malware and steal data.

Technical details

A use-after-free vulnerability exists in the Peer Objects component (iepeers.dll) of Microsoft Internet Explorer 6 and 7. The flaw is triggered when the browser attempts to access an invalid pointer after an object has been deleted from memory, often referred to as an 'Uninitialized Memory Corruption Vulnerability.' A remote attacker can exploit this by hosting a specially crafted webpage that, when viewed by a victim, triggers the memory corruption to execute arbitrary code with the privileges of the logged-in user. This vulnerability was notably exploited in the wild starting in March 2010. Microsoft addressed this issue in security bulletin MS10-018.

Affected products

  • Microsoft Internet Explorer 6, 6 SP1, 7

Timeline

  • 2010-03-09: advisory: Initial Microsoft security advisory released
  • 2010-03-11: exploited: Confirmed exploitation in the wild reported
  • 2010-03-30: patched: Formal patch released via MS10-018

Related threats