CVE-2008-4844

High PUBLISHED

Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1,...

Microsoft · Internet Explorer

Not yet in CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
9.3 High

At a Glance

Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML DSOs, or (3) Tabular Data Control (TDC) in a crafted HTML or XML document, as demonstrated by nested SPAN or MARQUEE elements, and exploited in the wild in December 2008.

metasploit
CVE Published
Dec 11, 2008
Exploitation Reported
Dec 11, 2008
CVSS
9.3 High
EPSS
Remote Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • HPSBST02397 marc.info · Vendor Advisory http://marc.info/?l=bugtraq&m=123015308222620&w=2
  • MS08-078 docs.microsoft.com · Vendor Advisory https://docs.microsoft.com/en-us/security-updates/securitybulletins/2...
  • TA08-352A us-cert.gov · Third-Party Advisory http://www.us-cert.gov/cas/techalerts/TA08-352A.html
  • VU#493881 kb.cert.org · Third-Party Advisory http://www.kb.cert.org/vuls/id/493881
  • TA08-344A us-cert.gov · Third-Party Advisory http://www.us-cert.gov/cas/techalerts/TA08-344A.html
Show 16 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.