Vulnerability record · CVE-2010-3971 · published 22 December 2010
CVE-2010-3971: Internet Explorer CSS parser use-after-free enables remote code execution
Microsoft · Internet Explorer
A use-after-free flaw exists in the CSharedStyleSheet::Notify function of the CSS parser in mshtml.dll, affecting Internet Explorer 6 through 8. A self-referential @import rule in a stylesheet triggers memory corruption, allowing remote code execution or a crash. The flaw is serious because it is reachable through normal browsing and has public exploit code.
Description
Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in mshtml.dll, as used in Microsoft Internet Explorer 6 through 8 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a self-referential @import rule in a stylesheet, aka "CSS Memory Corruption Vulnerability."
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 9.3, public exploit code, and very high EPSS make this a high-risk remote code execution flaw despite the lack of KEV listing.
What it is
A use-after-free flaw exists in the CSharedStyleSheet::Notify function of the CSS parser in mshtml.dll, affecting Internet Explorer 6 through 8. A self-referential @import rule in a stylesheet triggers memory corruption, allowing remote code execution or a crash. The flaw is serious because it is reachable through normal browsing and has public exploit code.
Impact
An attacker can execute arbitrary code in the context of the logged-on user or crash the browser. Successful exploitation gives the attacker the same rights as the victim, potentially leading to full system compromise.
Attack surface
Reached remotely over the network by getting a victim to load a crafted stylesheet in Internet Explorer; no authentication is required, but user interaction (visiting a page or opening a document) is needed per the AV:N/AC:M vector.
Exploitation
Public exploit code exists in Exploit-DB, Full Disclosure and other references, and EPSS is very high (0.81663, 99.6th percentile), though the CVE is not listed in CISA KEV.
What to do
- Apply Microsoft security update MS11-003, which addresses this vulnerability.
- Upgrade to a supported Internet Explorer version or a modern browser that is not affected.
- Disable or restrict ActiveX and script execution in Internet Explorer where feasible.
- Enforce network-level filtering or proxy inspection to block known exploit patterns for this flaw.
- Retire or isolate systems that still run Internet Explorer 6 through 8.
Detection
- Monitor for crashes of iexplore.exe or mshtml.dll, especially following visits to untrusted sites.
- Inspect web proxy and IDS logs for stylesheets containing self-referential @import rules.
- Hunt for known exploit signatures or payloads associated with CVE-2010-3971 in network traffic.
- Review endpoint logs for suspicious child processes spawned by Internet Explorer.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-3971 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-3971), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.