Vulnerability record · CVE-2009-0075 · published 10 February 2009
CVE-2009-0075: Internet Explorer 7 uninitialized memory corruption allows remote code execution
Microsoft · Internet Explorer
Microsoft Internet Explorer 7 mishandles errors when accessing deleted objects, specifically involving CFunctionPointer and the appending of document objects, leading to uninitialized memory corruption. A remote attacker can trigger this with a crafted HTML document and execute arbitrary code in the context of the browsing user.
Description
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to CFunctionPointer and the appending of document objects, aka "Uninitialized Memory Corruption Vulnerability."
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution with no authentication and public exploit code, though the affected product is a long-obsolete browser.
What it is
Microsoft Internet Explorer 7 mishandles errors when accessing deleted objects, specifically involving CFunctionPointer and the appending of document objects, leading to uninitialized memory corruption. A remote attacker can trigger this with a crafted HTML document and execute arbitrary code in the context of the browsing user.
Impact
Successful exploitation gives the attacker arbitrary code execution with the privileges of the logged-on user. Because IE 7 ran with full user rights on most systems, this typically means full control of the affected host.
Attack surface
The flaw is reached over the network by viewing a crafted HTML document in Internet Explorer 7; no authentication is required, but the victim must be lured into opening the page or a link to it (user interaction).
Exploitation
CISA KEV does not list this CVE, but EPSS is very high (0.85277, 99.7th percentile) and multiple Exploit-DB entries exist, indicating public exploit code is available.
What to do
- Apply Microsoft security bulletin MS09-002, which patches this vulnerability.
- Upgrade or migrate off Internet Explorer 7 to a supported browser.
- Enforce Protected Mode and current IE security zone settings where IE must remain in use.
- Block or restrict untrusted web content and known exploit hosts at the network boundary.
Detection
- Monitor for IE 7 processes (iexplore.exe) spawning child processes or making unexpected network connections.
- Hunt for crashes or memory corruption events in iexplore.exe tied to web browsing.
- Review proxy and DNS logs for known exploit-hosting domains and suspicious HTML delivery.
- Use endpoint detection to flag shellcode-like behavior originating from browser processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-0075 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-0075), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.