Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability

cve CVE-2010-3962 3 sources, 5 claims · Watch

CISA Known Exploited Vulnerabilities writes:
Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://learn.microsoft.com/en-us/security-updates/SecurityAdvisories/2010/2458511?redirectedfrom=MSDN ;… the claim

What each source says

PropertySourceSaidMeans here
Author
author
Exploit-DBMetasploit
receipt
Source
Exploit-DB
Its words
Metasploit
Read by
field:author
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-04 12:06 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Metasploit",
  "codes": "CVE-2010-3962;OSVDB-68987;MS10-090",
  "date_added": "2011-01-20",
  "date_published": "2011-01-20",
  "date_updated": "2011-03-10",
  "description": "Microsoft Internet Explorer - CSS SetUserClip Memory Corruption (MS10-090) (Metasploit)",
  "file": "exploits/windows/remote/16551.rb",
  "id": "16551",
  "platform": "windows",
  "port": "",
  "screenshot_url": "",
  "source_url": "http://www.microsoft.com/technet/security/advisory/2458511.mspx",
  "tags": "Metasploit Framework (MSF)",
  "type": "remote",
  "verified": "1"
}
—
Author
author
anonymous
receipt
Source
Exploit-DB
Its words
anonymous
Read by
field:author
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-04 12:06 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "anonymous",
  "codes": "CVE-2010-3962;OSVDB-69160;OSVDB-68987",
  "date_added": "2010-11-04",
  "date_published": "2010-11-04",
  "date_updated": "2017-11-03",
  "description": "Microsoft Internet Explorer - Memory Corruption",
  "file": "exploits/windows/dos/15418.html",
  "id": "15418",
  "platform": "windows",
  "port": "",
  "screenshot_url": "http://www.exploit-db.com/screenshots/idlt15500/screen-shot-2010-11-04-at-91605-am.png",
  "source_url": "",
  "tags": "",
  "type": "dos",
  "verified": "1"
}
—
Author
author
ryujin
receipt
Source
Exploit-DB
Its words
ryujin
Read by
field:author
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-04 12:06 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "ryujin",
  "codes": "CVE-2010-3962;OSVDB-69160;OSVDB-68987",
  "date_added": "2010-11-04",
  "date_published": "2010-11-04",
  "date_updated": "2010-11-06",
  "description": "Microsoft Internet Explorer 6/7/8 - Memory Corruption",
  "file": "exploits/windows/remote/15421.html",
  "id": "15421",
  "platform": "windows",
  "port": "",
  "screenshot_url": "http://www.exploit-db.com/screenshots/idlt15500/15421.png",
  "source_url": "",
  "tags": "",
  "type": "remote",
  "verified": "1"
}
—
Due date
due_date
CISA Known Exploited Vulnerabilities2025-10-27
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
2025-10-27
Read by
field:dueDate
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 15:15 UTC
What the source handed over
{
  "cveID": "CVE-2010-3962",
  "cwes": "",
  "dateAdded": "2025-10-06",
  "dueDate": "2025-10-27",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://learn.microsoft.com/en-us/security-updates/SecurityAdvisories/2010/2458511?redirectedfrom=MSDN ; https://nvd.nist.gov/vuln/detail/CVE-2010-3962",
  "product": "Internet Explorer",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.",
  "vendorProject": "Microsoft",
  "vulnerabilityName": "Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability"
}
—
Exploited
exploited
CISA Known Exploited Vulnerabilitiesyes
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
yes
Read by
const:yes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 15:15 UTC
What the source handed over
{
  "cveID": "CVE-2010-3962",
  "cwes": "",
  "dateAdded": "2025-10-06",
  "dueDate": "2025-10-27",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://learn.microsoft.com/en-us/security-updates/SecurityAdvisories/2010/2458511?redirectedfrom=MSDN ; https://nvd.nist.gov/vuln/detail/CVE-2010-3962",
  "product": "Internet Explorer",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.",
  "vendorProject": "Microsoft",
  "vulnerabilityName": "Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability"
}
—
Forensic triage
forensic_triage
CISA Known Exploited Vulnerabilitiesfalse
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
No
Read by
field:forensicTriage
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 15:15 UTC
What the source handed over
{
  "cveID": "CVE-2010-3962",
  "cwes": "",
  "dateAdded": "2025-10-06",
  "dueDate": "2025-10-27",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://learn.microsoft.com/en-us/security-updates/SecurityAdvisories/2010/2458511?redirectedfrom=MSDN ; https://nvd.nist.gov/vuln/detail/CVE-2010-3962",
  "product": "Internet Explorer",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.",
  "vendorProject": "Microsoft",
  "vulnerabilityName": "Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability"
}
—
Known ransomware campaign use
known_ransomware_campaign_use
CISA Known Exploited VulnerabilitiesUnknown
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Unknown
Read by
field:knownRansomwareCampaignUse
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 15:15 UTC
What the source handed over
{
  "cveID": "CVE-2010-3962",
  "cwes": "",
  "dateAdded": "2025-10-06",
  "dueDate": "2025-10-27",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://learn.microsoft.com/en-us/security-updates/SecurityAdvisories/2010/2458511?redirectedfrom=MSDN ; https://nvd.nist.gov/vuln/detail/CVE-2010-3962",
  "product": "Internet Explorer",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.",
  "vendorProject": "Microsoft",
  "vulnerabilityName": "Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability"
}
—
Platform
platform
not compared
Exploit-DBwindows
receipt
Source
Exploit-DB
Its words
windows
Read by
field:platform
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-04 12:06 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "anonymous",
  "codes": "CVE-2010-3962;OSVDB-69160;OSVDB-68987",
  "date_added": "2010-11-04",
  "date_published": "2010-11-04",
  "date_updated": "2017-11-03",
  "description": "Microsoft Internet Explorer - Memory Corruption",
  "file": "exploits/windows/dos/15418.html",
  "id": "15418",
  "platform": "windows",
  "port": "",
  "screenshot_url": "http://www.exploit-db.com/screenshots/idlt15500/screen-shot-2010-11-04-at-91605-am.png",
  "source_url": "",
  "tags": "",
  "type": "dos",
  "verified": "1"
}
—
Platform
platform
not compared
Metasploit exploit modulesWindows
receipt
Source
Metasploit exploit modules
Its words
Windows
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 15:04 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "",
  "author": [
    "unknown",
    "Yuange",
    "Matteo Memelli",
    "jduck <jduck@metasploit.com>"
  ],
  "autofilter_ports": [],
  "autofilter_services": [],
  "check": false,
  "default_credential": false,
  "description": "This module exploits a memory corruption vulnerability within Microsoft's\n          HTML engine (mshtml). When parsing an HTML page containing a specially\n          crafted CSS tag, memory corruption occurs that can lead arbitrary code\n          execution.\n\n          It seems like Microsoft code inadvertently increments a vtable pointer to\n          point to an unaligned address within the vtable's function pointers. This\n          leads to the program counter being set to the address determined by the\n          address \"[vtable+0x30+1]\". The particular address depends on the exact\n          version of the mshtml library in use.\n\n          Since the address depends on the version of mshtml, some versions may not\n          be exploitable. Specifically, those ending up with a program counter value\n          within another module, in kernel space, or just not able to be reached with\n          various memory spraying techniques.\n\n          Also, since the address is not controllable, it is unlikely to be possible\n          to use ROP to bypass non-executable memory protections.",
  "disclosure_date": "2010-11-03",
  "fullname": "exploit/windows/browser/ms10_090_ie_css_clip",
  "is_install_path": true,
  "mod_time": "2025-06-23 12:43:46 +0000",
  "name": "MS10-090 Microsoft Internet Explorer CSS SetUserClip Memory Corruption",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "unknown-reliability"
    ],
    "SideEffects": [
      "unknown-side-effects"
    ],
    "Stability": [
      "unknown-stability"
    ]
  },
  "path": "/modules/exploits/windows/browser/ms10_090_ie_css_clip.rb",
  "platform": "Windows",
  "post_auth": false,
  "rank": 400,
  "ref_name": "windows/browser/ms10_090_ie_css_clip",
  "references": [
    "CVE-2010-3962",
    "OSVDB-68987",
    "BID-44536",
    "EDB-15421",
    "MSB-MS10-090"
  ],
  "rport": null,
  "session_types": false,
  "targets": [
    "Automatic",
    "Debug",
    "Internet Explorer 6",
    "Internet Explorer 7"
  ],
  "type": "exploit"
}
—
Product
product
CISA Known Exploited VulnerabilitiesInternet Explorer
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Internet Explorer
Read by
field:product
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 15:15 UTC
What the source handed over
{
  "cveID": "CVE-2010-3962",
  "cwes": "",
  "dateAdded": "2025-10-06",
  "dueDate": "2025-10-27",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://learn.microsoft.com/en-us/security-updates/SecurityAdvisories/2010/2458511?redirectedfrom=MSDN ; https://nvd.nist.gov/vuln/detail/CVE-2010-3962",
  "product": "Internet Explorer",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.",
  "vendorProject": "Microsoft",
  "vulnerabilityName": "Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability"
}
—
Rank
rank
Metasploit exploit modules400
Good. A default target, reliable against the common configuration.
receipt
Source
Metasploit exploit modules
Its words
400
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 15:04 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "",
  "author": [
    "unknown",
    "Yuange",
    "Matteo Memelli",
    "jduck <jduck@metasploit.com>"
  ],
  "autofilter_ports": [],
  "autofilter_services": [],
  "check": false,
  "default_credential": false,
  "description": "This module exploits a memory corruption vulnerability within Microsoft's\n          HTML engine (mshtml). When parsing an HTML page containing a specially\n          crafted CSS tag, memory corruption occurs that can lead arbitrary code\n          execution.\n\n          It seems like Microsoft code inadvertently increments a vtable pointer to\n          point to an unaligned address within the vtable's function pointers. This\n          leads to the program counter being set to the address determined by the\n          address \"[vtable+0x30+1]\". The particular address depends on the exact\n          version of the mshtml library in use.\n\n          Since the address depends on the version of mshtml, some versions may not\n          be exploitable. Specifically, those ending up with a program counter value\n          within another module, in kernel space, or just not able to be reached with\n          various memory spraying techniques.\n\n          Also, since the address is not controllable, it is unlikely to be possible\n          to use ROP to bypass non-executable memory protections.",
  "disclosure_date": "2010-11-03",
  "fullname": "exploit/windows/browser/ms10_090_ie_css_clip",
  "is_install_path": true,
  "mod_time": "2025-06-23 12:43:46 +0000",
  "name": "MS10-090 Microsoft Internet Explorer CSS SetUserClip Memory Corruption",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "unknown-reliability"
    ],
    "SideEffects": [
      "unknown-side-effects"
    ],
    "Stability": [
      "unknown-stability"
    ]
  },
  "path": "/modules/exploits/windows/browser/ms10_090_ie_css_clip.rb",
  "platform": "Windows",
  "post_auth": false,
  "rank": 400,
  "ref_name": "windows/browser/ms10_090_ie_css_clip",
  "references": [
    "CVE-2010-3962",
    "OSVDB-68987",
    "BID-44536",
    "EDB-15421",
    "MSB-MS10-090"
  ],
  "rport": null,
  "session_types": false,
  "targets": [
    "Automatic",
    "Debug",
    "Internet Explorer 6",
    "Internet Explorer 7"
  ],
  "type": "exploit"
}
—
Type
type
Exploit-DBdos
receipt
Source
Exploit-DB
Its words
dos
Read by
field:type
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-04 12:06 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "anonymous",
  "codes": "CVE-2010-3962;OSVDB-69160;OSVDB-68987",
  "date_added": "2010-11-04",
  "date_published": "2010-11-04",
  "date_updated": "2017-11-03",
  "description": "Microsoft Internet Explorer - Memory Corruption",
  "file": "exploits/windows/dos/15418.html",
  "id": "15418",
  "platform": "windows",
  "port": "",
  "screenshot_url": "http://www.exploit-db.com/screenshots/idlt15500/screen-shot-2010-11-04-at-91605-am.png",
  "source_url": "",
  "tags": "",
  "type": "dos",
  "verified": "1"
}
—
Type
type
remote
receipt
Source
Exploit-DB
Its words
remote
Read by
field:type
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-04 12:06 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Metasploit",
  "codes": "CVE-2010-3962;OSVDB-68987;MS10-090",
  "date_added": "2011-01-20",
  "date_published": "2011-01-20",
  "date_updated": "2011-03-10",
  "description": "Microsoft Internet Explorer - CSS SetUserClip Memory Corruption (MS10-090) (Metasploit)",
  "file": "exploits/windows/remote/16551.rb",
  "id": "16551",
  "platform": "windows",
  "port": "",
  "screenshot_url": "",
  "source_url": "http://www.microsoft.com/technet/security/advisory/2458511.mspx",
  "tags": "Metasploit Framework (MSF)",
  "type": "remote",
  "verified": "1"
}
—
Vendor project
vendor_project
CISA Known Exploited VulnerabilitiesMicrosoft
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Microsoft
Read by
field:vendorProject
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 15:15 UTC
What the source handed over
{
  "cveID": "CVE-2010-3962",
  "cwes": "",
  "dateAdded": "2025-10-06",
  "dueDate": "2025-10-27",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://learn.microsoft.com/en-us/security-updates/SecurityAdvisories/2010/2458511?redirectedfrom=MSDN ; https://nvd.nist.gov/vuln/detail/CVE-2010-3962",
  "product": "Internet Explorer",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.",
  "vendorProject": "Microsoft",
  "vulnerabilityName": "Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability"
}
—
Verified
verified
Exploit-DBtrue
receipt
Source
Exploit-DB
Its words
1
Read by
field:verified
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-04 12:06 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "anonymous",
  "codes": "CVE-2010-3962;OSVDB-69160;OSVDB-68987",
  "date_added": "2010-11-04",
  "date_published": "2010-11-04",
  "date_updated": "2017-11-03",
  "description": "Microsoft Internet Explorer - Memory Corruption",
  "file": "exploits/windows/dos/15418.html",
  "id": "15418",
  "platform": "windows",
  "port": "",
  "screenshot_url": "http://www.exploit-db.com/screenshots/idlt15500/screen-shot-2010-11-04-at-91605-am.png",
  "source_url": "",
  "tags": "",
  "type": "dos",
  "verified": "1"
}
—

vulnerability

Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability
zetlyn/cve-kev · 2025-10-06
due_date 2025-10-27 exploited yes forensic_triage false known_ransomware_campaign_use Unknown product Internet Explorer vendor_project Microsoft

exploit

MS10-090 Microsoft Internet Explorer CSS SetUserClip Memory Corruption
zetlyn/cve-metasploit · 2010-11-03
platform Windows rank 400 source
Microsoft Internet Explorer - Memory Corruption
zetlyn/cve-exploitdb · 2010-11-04
author anonymous platform windows type dos verified true source
Microsoft Internet Explorer - CSS SetUserClip Memory Corruption (MS10-090) (Metasploit)
zetlyn/cve-exploitdb · 2011-01-20
author Metasploit platform windows type remote verified true source
Microsoft Internet Explorer 6/7/8 - Memory Corruption
zetlyn/cve-exploitdb · 2010-11-04
author ryujin platform windows type remote verified true source