Vulnerability Name: CVE-2010-0249 (CCN-55642) Assigned: 2010-01-14 Published: 2010-01-14 Updated: 2019-02-26 Summary: Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object, related to incorrectly initialized memory and improper handling of objects in memory, as exploited in the wild in December 2009 and January 2010 during Operation Aurora, aka "HTML Object Memory Corruption Vulnerability." CVSS v3 Severity: 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): ChangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
CVSS v2 Severity: 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C )7.7 High (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
9.3 High (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C )7.7 High (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
Vulnerability Type: CWE-399 Vulnerability Consequences: Gain Access References: Source: CONFIRM Type: Vendor Advisoryhttp://blogs.technet.com/msrc/archive/2010/01/14/security-advisory-979352.aspx Source: MITRE Type: CNACVE-2010-0249 Source: MISC Type: UNKNOWNhttp://news.cnet.com/8301-27080_3-10435232-245.html Source: OSVDB Type: UNKNOWN61697 Source: CCN Type: SA38209Microsoft Internet Explorer Multiple Vulnerabilities Source: CCN Type: SECTRACK ID: 1023462Microsoft Internet Explorer Invalid Pointer Reference Lets Remote Users Execute Arbitrary Code Source: SECTRACK Type: UNKNOWN1023462 Source: MSKB Type: Vendor Advisory979352 Source: CCN Type: Microsoft Security Bulletin MS11-099Cumulative Security Update for Internet Explorer (2618444) Source: CCN Type: Microsoft Security Bulletin MS12-010Cumulative Security Update for Internet Explorer (2647516) Source: CCN Type: Microsoft Security Bulletin MS12-023Cumulative Security Update for Internet Explorer (2675157) Source: CCN Type: Microsoft Security Bulletin MS12-037Cumulative Security Update for Internet Explorer (2699988) Source: CCN Type: Microsoft Security Bulletin MS12-044Cumulative Security Update for Internet Explorer (2719177) Source: CCN Type: Microsoft Security Bulletin MS12-052Cumulative Security Update for Internet Explorer (2722913) Source: EXPLOIT-DB Type: UNKNOWN11167 Source: CCN Type: IBM Internet Security Systems Protection AlertMicrosoft Internet Explorer Freed Object Code Execution Source: CCN Type: US-CERT VU#492515Microsoft Internet Explorer HTML object memory corruption vulnerability Source: CERT-VN Type: US Government ResourceVU#492515 Source: CCN Type: Microsoft Security Advisory (979352)Vulnerability in Internet Explorer Could Allow Remote Code Execution Source: CONFIRM Type: Vendor Advisoryhttp://www.microsoft.com/technet/security/advisory/979352.mspx Source: CCN Type: Microsoft Security Bulletin MS10-002Cumulative Security Update for Internet Explorer (978207) Source: CCN Type: Microsoft Security Bulletin MS10-018Cumulative Security Update for Internet Explorer (980182) Source: CCN Type: Microsoft Security Bulletin MS10-035Cumulative Security Update for Internet Explorer (982381) Source: CCN Type: Microsoft Security Bulletin MS10-053Cumulative Security Update for Internet Explorer (2183461) Source: CCN Type: Microsoft Security Bulletin MS10-071Cumulative Security Update for Internet Explorer (2360131) Source: CCN Type: Microsoft Security Bulletin MS10-090Cumulative Security Update for Internet Explorer (2416400) Source: CCN Type: Microsoft Security Bulletin MS11-003Cumulative Security Update for Internet Explorer (2482017) Source: CCN Type: Microsoft Security Bulletin MS11-018Cumulative Security Update for Internet Explorer (2497640) Source: CCN Type: Microsoft Security Bulletin MS11-050Cumulative Security Update for Internet Explorer (2530548) Source: CCN Type: Microsoft Security Bulletin MS11-057Cumulative Security Update for Internet Explorer (2559049) Source: CCN Type: Microsoft Security Bulletin MS11-081Cumulative Security Update for Internet Explorer (2586448) Source: CCN Type: OSVDB ID: 61697Microsoft IE mshtml.dll Use-After-Free Arbitrary Code Execution (Aurora) Source: BID Type: Exploit37815 Source: CCN Type: BID-37815Internet Explorer CVE-2010-0249 'srcElement()' Remote Code Execution Vulnerability Source: CERT Type: US Government ResourceTA10-055A Source: VUPEN Type: UNKNOWNADV-2010-0135 Source: MS Type: UNKNOWNMS10-002 Source: XF Type: UNKNOWNie-freed-object-code-execution(55642) Source: XF Type: UNKNOWNie-freed-object-code-execution(55642) Source: OVAL Type: UNKNOWNoval:org.mitre.oval:def:6835 Source: EXPLOIT-DB Type: EXPLOITOffensive Security Exploit Database [01-17-2010] Vulnerable Configuration: Configuration 1 :cpe:/a:microsoft:internet_explorer:6:*:*:*:*:*:*:* OR cpe:/a:microsoft:internet_explorer:6:sp1:*:*:*:*:*:* OR cpe:/a:microsoft:internet_explorer:7:*:*:*:*:*:*:* OR cpe:/a:microsoft:internet_explorer:8:*:*:*:*:*:*:* AND cpe:/o:microsoft:windows_2000:sp4:*:*:*:*:*:*:* Configuration 2 :cpe:/a:microsoft:internet_explorer:6:*:*:*:*:*:*:* OR cpe:/a:microsoft:internet_explorer:7:*:*:*:*:*:*:* OR cpe:/a:microsoft:internet_explorer:6:sp1:*:*:*:*:*:* OR cpe:/a:microsoft:internet_explorer:8:*:*:*:*:*:*:* AND cpe:/o:microsoft:windows_vista:*:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_vista:-:sp1:*:*:*:*:*:* OR cpe:/o:microsoft:windows_vista:-:sp2:*:*:*:*:*:* OR cpe:/o:microsoft:windows_server_2008:*:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:* OR cpe:/o:microsoft:windows_server_2008:r2:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_xp:-:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_xp:-:sp3:*:*:*:*:*:* OR cpe:/o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:* OR cpe:/o:microsoft:windows_7:*:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:* OR cpe:/a:microsoft:ie:6.0:sp1:*:*:*:*:*:* OR cpe:/a:microsoft:internet_explorer:7.0:*:*:*:*:*:*:* OR cpe:/a:microsoft:ie:8.0:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_server_2008:*:*:*:*:*:*:x32:* OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:itanium:* AND cpe:/o:microsoft:windows_2000:*:sp4:*:*:*:*:*:* OR cpe:/o:microsoft:windows:xp:sp2:*:*:*:*:*:* OR cpe:/o:microsoft:windows_vista:*:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows:server_2003:sp2:*:*:*:*:*:* OR cpe:/o:microsoft:windows:server_2003:sp2:itanium:*:*:*:*:* OR cpe:/o:microsoft:windows:server_2003:sp2:x64:*:*:*:*:* OR cpe:/o:microsoft:windows_vista:*:*:*:*:*:*:x64:* OR cpe:/o:microsoft:windows_xp::sp2:x64:*:professional:*:*:* OR cpe:/o:microsoft:windows_vista:*:sp1:*:*:*:*:*:* OR cpe:/o:microsoft:windows_vista:*:sp1:*:*:*:*:x64:* OR cpe:/o:microsoft:windows_server_2008:*:*:*:*:*:*:itanium:* OR cpe:/o:microsoft:windows_server_2008:*:*:*:*:*:*:x64:* OR cpe:/o:microsoft:windows:xp:sp3:*:*:*:*:*:* OR cpe:/o:microsoft:windows_vista:*:sp2:*:*:*:*:x64:* OR cpe:/o:microsoft:windows_vista:*:sp2:*:*:*:*:*:* OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x32:* OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x64:* OR cpe:/o:microsoft:windows_7:*:*:*:*:*:*:x64:* OR cpe:/o:microsoft:windows_7:-:*:*:*:*:*:x32:* OR cpe:/o:microsoft:windows_server_2008:*:r2:x64:*:*:*:*:* OR cpe:/o:microsoft:windows_server_2008:*:r2:itanium:*:*:*:*:* Denotes that component is vulnerable Oval Definitions BACK
microsoft internet explorer 6
microsoft internet explorer 6 sp1
microsoft internet explorer 7
microsoft internet explorer 8
microsoft windows 2000 sp4
microsoft internet explorer 6
microsoft internet explorer 7
microsoft internet explorer 6 sp1
microsoft internet explorer 8
microsoft windows vista *
microsoft windows vista - sp1
microsoft windows vista - sp2
microsoft windows server 2008 -
microsoft windows server 2008 - sp2
microsoft windows server 2008 r2
microsoft windows xp -
microsoft windows xp sp3
microsoft windows server 2003 * sp2
microsoft windows 7 *
microsoft ie 6.0
microsoft ie 6.0 sp1
microsoft ie 7.0
microsoft ie 8.0
microsoft windows server 2008 -
microsoft windows server 2008
microsoft windows 2000 * sp4
microsoft windows xp sp2
microsoft windows vista *
microsoft windows server_2003 sp2
microsoft windows server_2003 sp2
microsoft windows server_2003 sp2
microsoft windows vista *
microsoft windows xp sp2
microsoft windows vista * sp1
microsoft windows vista * sp1
microsoft windows server 2008
microsoft windows server 2008 -
microsoft windows xp sp3
microsoft windows vista * sp2
microsoft windows vista * sp2
microsoft windows server 2008 sp2
microsoft windows server 2008 sp2
microsoft windows 7 *
microsoft windows 7 -
microsoft windows server 2008 * r2
microsoft windows server 2008 * r2