ZeroHour

CVE-2012-2539

KEVmass

Remote Code Execution in Microsoft Word via Crafted RTF Documents

CISA: Microsoft Word Remote Code Execution Vulnerability

CVSS
EPSS
53%p99
Published
KEV added
AI analysis

CVE-2012-2539 is a remote code execution flaw in Microsoft Word that mishandles crafted RTF (Rich Text Format) data, allowing an attacker to execute arbitrary code as the logged-in user or crash Word in a denial of service. The flaw is triggered when Word processes a malicious RTF document, typically delivered as an email attachment or downloaded file; because Word also renders RTF content, simply opening or previewing attacker-supplied content can be enough to trigger it. Any user of an affected, unpatched Word installation who opens untrusted RTF documents is exposed; Microsoft shipped the fix in its December 2012 Word security bulletin (MS12-079). The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-28), confirming exploitation in the wild, and EPSS assigns a 53.2% probability of exploitation within 30 days (99th percentile), though no public PoC is known and ransomware use is unknown.

What to do: Apply the Microsoft Word security update from the December 2012 bulletin (MS12-079) on any Office install still in service, per CISA's required action to apply vendor updates. Until patched, do not open RTF documents from untrusted sources and confirm whether legacy 2012-era Word builds remain in use in your environment.

Affected
Microsoft WordMicrosoft Word (affected version ranges not enumerated in source data; all Word builds supported by Microsoft at disclosure in 2012, fixed in the December 2012
Estimated exposure
mass≫1M Word installations worldwide (hundreds of millions of Office seats deployed; residual unpatched legacy installs plausibly in the millions) — Word ships with Microsoft Office, which has hundreds of millions of deployed seats, so even a small unpatched-legacy fraction puts exposure above the mass threshold; exact counts of remaining unpatched systems are unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data.

CISA Known Exploited Vulnerability
Affected
Microsoft Word
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Word
Weakness
CWE-399

In the news