Vulnerability record · CVE-2010-0805 · published 31 March 2010
CVE-2010-0805: Internet Explorer TDC ActiveX control memory corruption RCE
Microsoft · Internet Explorer
The Tabular Data Control (TDC) ActiveX control in Internet Explorer fails to properly validate the DataURL parameter, allowing a long URL to trigger memory corruption in CTDCCtl::SecurityCHeckDataURL. Successful exploitation lets a remote attacker run arbitrary code in the context of the logged-on user. The flaw affects IE 5.01 SP4, IE 6 on Windows XP SP2/SP3, and IE 6 SP1.
Description
The Tabular Data Control (TDC) ActiveX control in Microsoft Internet Explorer 5.01 SP4, 6 on Windows XP SP2 and SP3, and 6 SP1 allows remote attackers to execute arbitrary code via a long URL (DataURL parameter) that triggers memory corruption in the CTDCCtl::SecurityCHeckDataURL function, aka "Memory Corruption Vulnerability."
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityCVSS 9.3 remote code execution with a very high EPSS score, though the affected IE versions are long obsolete and no KEV listing or active exploitation is documented.
What it is
The Tabular Data Control (TDC) ActiveX control in Internet Explorer fails to properly validate the DataURL parameter, allowing a long URL to trigger memory corruption in CTDCCtl::SecurityCHeckDataURL. Successful exploitation lets a remote attacker run arbitrary code in the context of the logged-on user. The flaw affects IE 5.01 SP4, IE 6 on Windows XP SP2/SP3, and IE 6 SP1.
Impact
An attacker gains arbitrary code execution with the privileges of the victim's user account, enabling malware installation, data theft, or further compromise of the host.
Attack surface
Reached over the network via a crafted web page or link that instantiates the TDC ActiveX control with a malicious DataURL; no authentication is required, but the victim must be lured into viewing the content (user interaction).
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.806, 99.6th percentile) and references include a ZDI advisory and Microsoft security bulletin MS10-018, indicating public technical detail and available patches.
What to do
- Apply Microsoft security bulletin MS10-018 (or the corresponding cumulative IE update) to affected systems.
- Upgrade from Internet Explorer 5.01/6 to a supported browser version on Windows XP and Windows 2000.
- Disable or block the TDC ActiveX control via IE's ActiveX kill-bit or add-on management where legacy IE must remain.
- Restrict browsing to trusted sites and enforce network-level filtering of untrusted content for systems that cannot be patched.
Detection
- Monitor for IE processes (iexplore.exe) spawning unexpected child processes or writing executables to user-writable paths.
- Look for crash or exploit telemetry referencing CTDCCtl::SecurityCHeckDataURL or the TDC ActiveX control in endpoint logs.
- Hunt for network or proxy logs showing IE retrieving pages that instantiate the TDC control with unusually long DataURL parameters.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-0805 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-0805), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.