Junglewise Threat Intelligence

CVE-2010-3962: Microsoft Internet Explorer use-after-free in CSS processing

CVE-2010-3962 · Severity: critical · CVSS 9.3 · Exploited in the wild · Published 2025-10-06

Technologies: Microsoft Edge, Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

Internet Explorer is a legacy web browser used to access the internet and internal web applications. A critical vulnerability allows an attacker to take complete control of a user's computer if they visit a malicious website. This could lead to the theft of sensitive data, installation of malware, or total disruption of business operations. Because these versions of Internet Explorer are end-of-life, users should immediately switch to a modern, supported browser.

Technical details

A use-after-free vulnerability exists in Microsoft Internet Explorer 6, 7, and 8 due to improper handling of Cascading Style Sheets (CSS) token sequences and the 'clip' attribute. This is often referred to as an 'invalid flag reference' or uninitialized memory corruption issue. A remote attacker can exploit this by enticing a user to visit a malicious webpage, leading to arbitrary code execution in the context of the current user. The vulnerability was notably exploited in the wild as a zero-day in 2010. Microsoft released a patch under bulletin MS10-090, though the affected browser versions are now considered end-of-life.

Affected products

  • Microsoft Internet Explorer 6
  • Microsoft Internet Explorer 7
  • Microsoft Internet Explorer 8

Timeline

  • 2010-11-02: advisory: Microsoft released security advisory 2458511
  • 2010-11-01: exploited: Exploitation in the wild reported in November 2010
  • 2025-10-06: kev added: Added to CISA Known Exploited Vulnerabilities catalog

Related threats