CVE-2010-0249 is a use-after-free memory-corruption vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8. Incorrect initialization and lifecycle handling of HTML objects can leave a pointer associated with a deleted object accessible. A crafted HTML page, or a Microsoft Office document that causes the browser to process malicious HTML content, can dereference the invalid pointer and corrupt memory. The vulnerability was exploited in the Operation Aurora attacks in late 2009 and early 2010.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit module: 'ms10_002_aurora.rb', which exploits a memory corruption vulnerability (CVE-2010-0249) in Microsoft Internet Explorer 6. The exploit was used in the 'Operation Aurora' attacks and allows remote code execution when a victim visits a malicious web page served by the attacker. The module sets up an HTTP server that delivers a specially crafted HTML/JavaScript page. The JavaScript performs a heap spray and triggers the vulnerability, allowing the attacker's payload (such as a reverse shell) to execute on the victim's system. The exploit is operational and customizable via Metasploit's payload system. The only endpoints exposed are the HTTP server delivering the exploit and a GIF image used in the exploit chain. The code is written in Ruby (Metasploit module), with embedded JavaScript and HTML for the client-side attack. The exploit specifically targets Internet Explorer 6 on Windows.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Internet Explorer use-after-free vulnerability allowing arbitrary code execution.
A critical use-after-free vulnerability in Microsoft Internet Explorer that allows remote code execution via malicious web content.
A use-after-free remote code execution vulnerability in Microsoft Internet Explorer.
A Microsoft Internet Explorer use-after-free memory corruption vulnerability enabling remote code execution through malicious web pages.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.