Junglewise Threat Intelligence

CVE-2012-1856: Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability

CVE-2012-1856 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-03-03

Technologies: Microsoft SQL Server, Microsoft Office. Vendors: Microsoft.

Executive brief

The TabStrip ActiveX control in MSCOMCTL.OCX allows remote attackers to execute arbitrary code via crafted documents or web pages. The vulnerability stems from system-state corruption during the handling of the control, affecting various Microsoft Office and server products.

Affected products

  • Microsoft Office 2003 SP3, 2007 SP2, 2007 SP3, 2010 SP1
  • Microsoft Office Web Components 2003 SP3
  • Microsoft SQL Server 2000 SP4, 2005 SP4, 2008 SP2, 2008 SP3, 2008 R2, 2008 R2 SP1, 2008 R2 SP2
  • Microsoft Commerce Server 2002 SP4, 2007 SP2, 2009 Gold, 2009 R2
  • Microsoft Host Integration Server 2004 SP1
  • Microsoft Visual FoxPro 8.0 SP1, 9.0 SP2
  • Microsoft Visual Basic Runtime 6.0

Timeline

  • 2012-08-14: patched: Microsoft Security Bulletin MS12-060 released.
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-03-03: disclosed: NVD publication date.

Related threats