Microsoft Internet Explorer Use-After-Free Vulnerability

Release Date: 15th May 2026

Impact : HIGH / CRITICAL

TLP Rating: Clear

The Department of Communication and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2010-0249 is a critical remote code execution (RCE) vulnerability in Microsoft Internet Explorer. The flaw is caused by a memory corruption/use-after-free vulnerability in the way Internet Explorer handles certain HTML objects and cascading style sheets

When a user visits a specially crafted malicious webpage, Internet Explorer may improperly access freed memory, allowing attackers to execute arbitrary code on the victim’s system.

 

References

  1. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  2. https://www.cve.org/CVERecord?id=CVE-2010-0249