← back
CVE-2008-4844observed exploitation

CVE-2008-4844

72Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 67%
from disclosure to weapon648 days
Published on NVDDec 11
1st PoC+648d
metasploitDec 7
VulnCheckDec 11
exploitation probability
67%top 1% of all CVEs
observed exploitation
yesVulnCheck
5 public exploit(s)
Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML DSOs, or (3) Tabular Data Control (TDC) in a crafted HTML or XML document, as demonstrated by nested SPAN or MARQUEE elements, and exploited in the wild in December 2008.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.