Executive brief
The ListView, TreeView, and other ActiveX controls in MSCOMCTL.OCX contain a vulnerability that allows remote code execution via crafted websites, Office documents, or RTF files. Successful exploitation triggers system state corruption, allowing an attacker to take complete control of the affected system.
Affected products
- Microsoft Office 2003 SP3, 2007 SP2/SP3, 2010 Gold/SP1
- Microsoft Office 2003 Web Components SP3
- Microsoft SQL Server 2000 SP4, 2005 SP4, 2008 SP2/SP3/R2
- Microsoft BizTalk Server 2002 SP1
- Microsoft Commerce Server 2002 SP4, 2007 SP2, 2009 Gold/R2
- Microsoft Visual FoxPro 8.0 SP1, 9.0 SP2
- Microsoft Visual Basic 6.0 Runtime
Timeline
- 2012-04: exploited: Exploited in the wild in April 2012.
- 2012-04-10: patched: Microsoft released security bulletin MS12-027.
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.