Skip to content
COOEY

EXPOSURES › CVE-2010-0249

CVE-2010-0249

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-05-20 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2010-0249 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 45/100 rceexploited-in-wildransomwareunpatched

Microsoft Internet Explorer use-after-free vulnerability (CVE-2010-0249) allows remote code execution on EoL browsers.

This use-after-free flaw enables remote attackers to execute arbitrary code on Internet Explorer, a product Microsoft has marked as end-of-life and end-of-service. DIB organizations must ensure no legacy IE usage remains in their environments to avoid exploitation via compromised web content.

Shame score — While the vulnerability is actively exploited and linked to ransomware, the vendor has publicly disclosed it and marked the product as EoL, reducing the avoidability compared to negligent defaults.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized