Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2010-0806

97
FAUCET Score

CVE-2010-0806 is a critical use-after-free vulnerability in the Peer Objects component (iepeers.dll) of Microsoft Internet Explorer versions 6, 6 SP1, and 7, affecting various Windows operating systems. This flaw allows remote attackers to execute arbitrary code by manipulating invalid pointers after an object's deletion. With a CVSS score of 9.3, it presents a high severity risk due to its network-based attack vector, medium attack complexity, and complete compromise of confidentiality, integrity, and availability. The vulnerability was actively exploited in the wild in March 2010, and public exploit code, including Metasploit modules, is available, despite a lack of recent community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
5.01CPE matchmatch criteria
cpe:2.3:a:microsoft:internet_explorer:5.01:*:*:*:*:*:*:*
6CPE matchmatch criteria
cpe:2.3:a:microsoft:internet_explorer:6:sp1:*:*:*:*:*:*
8CPE matchmatch criteria
cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:*
7CPE matchmatch criteria
cpe:2.3:a:microsoft:internet_explorer:7:*:*:*:*:*:*:*
6CPE matchmatch criteria
cpe:2.3:a:microsoft:internet_explorer:6:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

9.3HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
82.17%
Probability of exploitation in next 30 days
EPSS Percentile
99.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Added to KEV · May 20, 2026
Metasploit: MS10-018 Microsoft Internet Explorer DHTML Behaviors Use After Free · Mar 9, 2010
ExploitDB: EDB-16590 · Dec 14, 2010
This CVE's current EPSS score of 0.8217 is in the 100th percentile among its peer group of 14,825 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

microsoftpatch availablevia nvd_reference
View patch

References

learn.microsoft.com / en-us/security-updates/securitybulletins/2010/ms10-018
Vendor Advisory
cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
blogs.technet.com / msrc/archive/2010/03/09/security-advisory-981374-released.aspx
Broken Link
osvdb.org / 62810
Broken Link
docs.microsoft.com / en-us/security-updates/securitybulletins/2010/ms10-018
Vendor Advisory
secunia.com / advisories/38860
Vendor Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/56772
Third Party AdvisoryVDB Entry
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8446
Broken Link
kb.cert.org / vuls/id/744549
PatchUS Government Resource
microsoft.com / technet/security/advisory/981374.mspx
Broken LinkPatchVendor Advisory
securityfocus.com / bid/38615
Broken Link
us-cert.gov / cas/techalerts/TA10-068A.html
US Government Resource
us-cert.gov / cas/techalerts/TA10-089A.html
US Government Resource
vupen.com / english/advisories/2010/0567
Vendor Advisory
vupen.com / english/advisories/2010/0744
Vendor Advisory