ZeroHour

CVE-2012-1856

KEVmass

Remote Code Execution via TabStrip ActiveX Control in Microsoft Office (MSCOMCTL.OCX)

CISA: Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability

CVSS
EPSS
72%p99
Published
KEV added
AI analysis

CVE-2012-1856 is a remote code execution flaw in the TabStrip ActiveX control in the Common Controls library (MSCOMCTL.OCX) that ships with Microsoft Office, classified as code injection (CWE-94). An attacker triggers it by getting a victim to open a specially crafted document or browse to a crafted web page that instantiates the control and corrupts the system state, allowing arbitrary code execution in the context of the user. Successful exploitation gives the attacker the privileges of the logged-on user, enabling malware delivery or lateral movement, which matches the weaponized-document patterns seen in APT campaigns referenced in related reporting. Any user of Microsoft Office where the vulnerable control is present and loadable from untrusted documents or web content is affected. Exploitation is confirmed in the wild: the flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03) and EPSS assigns a 72.2% probability of exploitation within 30 days (99th percentile), though no public proof-of-concept code is known.

What to do: Apply Microsoft's Office security updates per vendor instructions, as required by the CISA KEV catalog, and verify on legacy systems that MSCOMCTL.OCX has actually been updated rather than assumed. Restrict or prompt on ActiveX control instantiation from untrusted documents and web pages, and hunt for spearphishing documents or web content that exercises the TabStrip control, given the APT and malware-tooling activity noted in related reporting.

Affected
Microsoft Office (MSCOMCTL.OCX Common Controls, TabStrip ActiveX control)
Estimated exposure
mass≈100M+ Office installations potentially carry the vulnerable control; actual current exposure is far lower because vendor updates have been available since… — Microsoft Office runs on hundreds of millions of devices worldwide and MSCOMCTL.OCX ships with it, so the potential install base is mass-scale, but the flaw was patchable via vendor updates for over a decade, so residual exposure…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption.

CISA Known Exploited Vulnerability
Affected
Microsoft Office
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Office
Weakness
CWE-94

In the news