Vulnerability record · CVE-2010-0806 · published 10 March 2010
CVE-2010-0806: Microsoft Internet Explorer Peer Objects use-after-free allows remote code execution
Microsoft · Internet Explorer
Internet Explorer 6, 6 SP1 and 7 contain a use-after-free in the Peer Objects component (iepeers.dll), where an object is accessed after deletion, leaving an invalid pointer. Microsoft's advisory labels it an uninitialized memory corruption issue, and it was exploited in the wild in March 2010. Because the flaw is in a core browser component reachable from web content, it matters for any environment still running these IE versions.
Description
Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the wild in March 2010, aka "Uninitialized Memory Corruption Vulnerability."
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is listed in CISA KEV with confirmed in-the-wild exploitation, has a very high EPSS score, and allows unauthenticated remote code execution via browsing.
What it is
Internet Explorer 6, 6 SP1 and 7 contain a use-after-free in the Peer Objects component (iepeers.dll), where an object is accessed after deletion, leaving an invalid pointer. Microsoft's advisory labels it an uninitialized memory corruption issue, and it was exploited in the wild in March 2010. Because the flaw is in a core browser component reachable from web content, it matters for any environment still running these IE versions.
Impact
A remote attacker can execute arbitrary code in the context of the logged-on user, giving full control of the affected system. Successful exploitation typically results in malware installation or data theft under the user's privileges.
Attack surface
Reached over the network by a victim visiting a crafted web page or opening attacker-supplied content that triggers the Peer Objects component. No authentication is required, but user interaction (browsing to or opening the malicious content) is needed per the CVSS vector UI:R.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog with a due date of 2026-06-03, and the description states it was exploited in the wild in March 2010. EPSS is very high at 0.82172 (99.6th percentile), and references include vendor and US-CERT advisories plus patch information.
What to do
- Apply the Microsoft security update for Internet Explorer (MS10-018) or the vendor mitigation in Security Advisory 981374 as the first action.
- If patching is not possible, discontinue use of Internet Explorer 6/6 SP1/7 or restrict browsing to trusted sites only.
- Enforce the CISA KEV required action and BOD 22-01 guidance for cloud services, and track remediation against the 2026-06-03 due date.
- Reduce exposure by disabling or unregistering the iepeers.dll Peer Objects component where operationally feasible.
- Run browsing with least privilege and block untrusted web content at the network boundary.
Detection
- Hunt for IE 6/6 SP1/7 processes loading iepeers.dll and crashing or spawning unexpected child processes.
- Monitor for exploit-related network traffic and drive-by download patterns tied to March 2010 campaign activity.
- Review endpoint telemetry for code execution originating from iexplore.exe outside normal browser behavior.
- Check asset inventories for hosts still running the affected IE versions and confirm patch state against MS10-018.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2010-0806 to the Known Exploited Vulnerabilities catalog on 20 May 2026 as "Microsoft Internet Explorer Use-After-Free Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 3 June 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-0806 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-0806), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.