CVE-2010-0806
Act now ● On CISA KEV — actively exploited
Actively exploited — on the CISA KEV list.
CVSS base
—
EPSS — probability of exploitation (30 days)
82.2%
99.6th percentile
CISA KEV
Listed
Added 2026-05-20 · patch by 2026-06-03
Weakness / dates
—
Published — · modified —
Timeline
- 2026-05-20 — Added to CISA KEV (actively exploited)
- 2026-06-03 — CISA patch-by deadline
Description
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.