Use-after-free vulnerability in Internet Explorer 6-8 that allows remote code execution when users visit malicious websites. This was famously exploited in Operation Aurora attacks but requires user interaction to visit attacker-controlled content.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: USER_INTERACTION
CVE Published: 2010-01-15
Added to CISA KEV: 2026-05-20 5969 DAYS BETWEEN CVE AND KEV
CVE-2010-0249 is a significant historical vulnerability in Microsoft Internet Explorer, most famously known for its role in the "Operation Aurora" cyberattacks.
Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2. ... Secure .gov websites use HTTPS A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on officiaβ¦
Vulnerability Details : CVE-2010-0249 Public exploit exists! Microsoft Internet Explorer Use-After-Free Vulnerability Allows Remote Code Execution (Operation Aurora)β¦
The vulnerability addressed is the HTML Object Memory Corruption Vulnerability - CVE-2010-0249. Other Information. Feedback. You can provide ...