CVE detail
CVE-2010-0806 — Microsoft Internet Explorer Use-After-Free Vulnerability
Published 2026-05-20 · Modified 2026-05-20 · Source kev
HIGH
severity
CVSS-derived band
0.8217
EPSS probability
exploitation probability, 30d
100.0%
EPSS percentile
percentile vs all CVEs
LISTED
CISA KEV
due 2026-06-03
⚠ Actively exploited in the wild — CISA KEV listed 2026-05-20, federal remediation due 2026-06-03.
Description
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References