Executive brief
The TabStrip ActiveX control in MSCOMCTL.OCX allows remote attackers to execute arbitrary code via crafted documents or web pages. The vulnerability stems from system-state corruption during the handling of the control, affecting various Microsoft Office and server products.
Affected products
- Microsoft Office 2003 SP3, 2007 SP2, 2007 SP3, 2010 SP1
- Microsoft Office Web Components 2003 SP3
- Microsoft SQL Server 2000 SP4, 2005 SP4, 2008 SP2, 2008 SP3, 2008 R2, 2008 R2 SP1, 2008 R2 SP2
- Microsoft Commerce Server 2002 SP4, 2007 SP2, 2009 Gold, 2009 R2
- Microsoft Host Integration Server 2004 SP1
- Microsoft Visual FoxPro 8.0 SP1, 9.0 SP2
- Microsoft Visual Basic Runtime 6.0
Timeline
- 2012-08-14: patched: Microsoft Security Bulletin MS12-060 released.
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2022-03-03: disclosed: NVD publication date.