First published: Fri Jan 22 2010(Updated: )
Microsoft Internet Explorer 5.01 SP4, 6, and 6 SP1 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =6-sp1 | |
Microsoft Windows 2000 | =sp4 | |
Internet Explorer | =6 | |
Internet Explorer | =6.0 | |
Internet Explorer | =6.00.2462.0000 | |
Internet Explorer | =6.00.2479.0006 | |
Internet Explorer | =6.0.2600 | |
Internet Explorer | =6.00.2600.0000 | |
Internet Explorer | =6.0.2800 | |
Internet Explorer | =6.0.2800.1106 | |
Internet Explorer | =6.00.2800.1106 | |
Internet Explorer | =6.0.2900 | |
Internet Explorer | =6.0.2900.2180 | |
Internet Explorer | =6.00.2900.2180 | |
Internet Explorer | =6.00.3663.0000 | |
Internet Explorer | =6.00.3718.0000 | |
Internet Explorer | =6.00.3790.0000 | |
Internet Explorer | =6.00.3790.1830 | |
Internet Explorer | =6.00.3790.3959 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp3 | |
Microsoft Windows XP | =sp2 | |
Internet Explorer | =5.01-sp4 | |
All of | ||
Internet Explorer | =6-sp1 | |
Microsoft Windows 2000 | =sp4 | |
All of | ||
Any of | ||
Internet Explorer | =6 | |
Internet Explorer | =6.0 | |
Internet Explorer | =6.00.2462.0000 | |
Internet Explorer | =6.00.2479.0006 | |
Internet Explorer | =6.0.2600 | |
Internet Explorer | =6.00.2600.0000 | |
Internet Explorer | =6.0.2800 | |
Internet Explorer | =6.0.2800.1106 | |
Internet Explorer | =6.00.2800.1106 | |
Internet Explorer | =6.0.2900 | |
Internet Explorer | =6.0.2900.2180 | |
Internet Explorer | =6.00.2900.2180 | |
Internet Explorer | =6.00.3663.0000 | |
Internet Explorer | =6.00.3718.0000 | |
Internet Explorer | =6.00.3790.0000 | |
Internet Explorer | =6.00.3790.1830 | |
Internet Explorer | =6.00.3790.3959 | |
Any of | ||
Microsoft Windows Server | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp3 | |
Microsoft Windows XP | =sp2 | |
All of | ||
Internet Explorer | =5.01-sp4 | |
Microsoft Windows 2000 | =sp4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0247 has a critical severity rating due to its potential to allow remote attackers to execute arbitrary code.
To fix CVE-2010-0247, users should apply the latest security updates provided by Microsoft for Internet Explorer.
CVE-2010-0247 affects Microsoft Internet Explorer versions 5.01 SP4, 6, and 6 SP1.
Yes, CVE-2010-0247 can impact systems running Internet Explorer on Windows 2000 and Windows XP if the affected versions are in use.
CVE-2010-0247 is exploitable remotely and can execute code without user interaction through malicious crafted web pages.