CVE-2010-0249CISA KEV
Microsoft Internet Explorer Use-After-Free Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
- Product
- Internet Explorer
- Added to KEV
- 20 May 2026
- Federal remediation due
- 3 Jun 2026
- Known ransomware use
- Not reported