CVE-2010-3962

9.5 CISA KEV

Microsoft · Internet Explorer

A use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via crafted CSS token sequences and the clip attribute.

Executive summary

This critical use-after-free vulnerability in legacy Microsoft Internet Explorer versions is confirmed to be actively exploited in the wild, posing an extreme risk of remote code execution.

Vulnerability

This is a use-after-free vulnerability that occurs during the processing of Cascading Style Sheets (CSS) token sequences and the clip attribute. The flaw allows an unauthenticated remote attacker to execute arbitrary code on the host system.

Business impact

The vulnerability carries a critical CVSS score of 9.5, reflecting the high potential for total system compromise. Successful exploitation results in remote code execution, which grants attackers the ability to install malicious software, access sensitive data, or establish persistent control over the affected workstation. Given the legacy nature of the software, these systems are often poorly protected, significantly increasing the probability of a successful, damaging breach.

Remediation

Immediate Action: Apply the security update provided in MS10-090 (KB2416400) immediately. If the software cannot be patched, discontinue use of the affected browser versions as they are no longer supported and remain highly vulnerable.

Proactive Monitoring: Monitor network traffic for unusual outbound connections from workstations running legacy browser versions. Review system logs for unexpected process execution or unauthorized modifications to system files.

Compensating Controls: Deploy a Web Application Firewall (WAF) or endpoint protection solution to detect and block malicious CSS-based payloads. Restrict Internet Explorer access to trusted, isolated environments if complete removal is not immediately feasible.

Exploitation status

Public Exploit Available: Yes, a Metasploit module and ExploitDB entry exist.

Analyst recommendation

Due to the critical severity and confirmed status of this vulnerability in the CISA Known Exploited Vulnerabilities catalog, immediate remediation is required. Organizations must prioritize patching or, preferably, the total decommissioning of Microsoft Internet Explorer 6, 7, and 8. Failure to address this flaw leaves systems exposed to active, high-impact exploitation.

More Microsoft CVEs

Sources