| TSL ID | FSC20100309-03 |
| CVE ID(s) | CVE-2010-0806 |
| Severity | High |
| Description | A code execution vulnerability exists in Microsoft Internet Explorer. The vulnerability is due to an invalid pointer reference being used after an object is deleted. This vulnerability may be exploited by remote unauthenticated attackers to execute arbitrary code on the target machine by enticing a user into opening a specially crafted HTML document. In attack scenarios where code execution is successful the behaviour of the target machine would depend entirely on the intention of the injected code, which would run within the security context of the logged on user. In situations where code execution is not successful, the vulnerable application may terminate abnormally, leading to a denial of service condition. The vendor, Microsoft, has released patches to address this vulnerability: http://www.microsoft.com/technet/security/Bulletin/MS10-018.mspx |
| Affected Products |
|
| CVSS Score |
Base 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P):
|