CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
Percentile
99.8%
Microsoft Internet Explorer invalid flag reference vulnerability
According to the Microsoft Security Research & Defense Blog, Microsoft Internet Explorer incorrectly under-allocates memory to store a certain combination of Cascading Style Sheets (CSS) tags when parsing HTML, resulting in an overwrite of the least significant byte of a vtable pointer. The Microsoft Security Advisory (2458511) refers to the vulnerability as an invalid flag reference vulnerability, where the reference to an object can be accessed after it is deleted.
Exploit code for this vulnerability is publicly available.
By convincing a user to view a specially crafted HTML document (e.g., a web page or an HTML email message or attachment), an attacker may be able to execute arbitrary code with the privileges of the user.
Apply an update
This issue is addressed in Microsoft Security Bulletin MS10-090.
Workarounds
Microsoft has listed several workarounds in Microsoft Security Advisory (2458511).
899748
Filter by status: All Affected Not Affected Unknown
Filter by content: __ Additional information available
__ Sort by: Status Alphabetical
Expand all
Javascript is disabled. Click here to view vendors.
Updated: January 18, 2011
Affected
We have not received a statement from the vendor.
We are not aware of further vendor information regarding this vulnerability.
Group | Score | Vector |
---|---|---|
Base | 0 | AV:–/AC:–/Au:–/C:–/I:–/A:– |
Temporal | 0 | E:ND/RL:ND/RC:ND |
Environmental | 0 | CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND |
Thanks to Microsoft Security Response Center for reporting this vulnerability, who in turn credit Symantec.
This document was written by Michael Orlando.
CVE IDs: | CVE-2010-3962 |
---|---|
Severity Metric: | 54.62 Date Public: |
blogs.technet.com/b/srd/archive/2010/11/03/dep-emet-protect-against-attacks-on-the-latest-internet-explorer-vulnerability.aspx
support.microsoft.com/kb/2458511
www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3962
www.exploit-db.com/exploits/15421/
www.microsoft.com/technet/security/advisory/2458511.mspx
www.microsoft.com/technet/security/bulletin/MS10-090.mspx