CVE-2012-2539
KEVmassRemote Code Execution in Microsoft Word via Crafted RTF Documents
CISA: Microsoft Word Remote Code Execution Vulnerability
CVE-2012-2539 is a remote code execution flaw in Microsoft Word that mishandles crafted RTF (Rich Text Format) data, allowing an attacker to execute arbitrary code as the logged-in user or crash Word in a denial of service. The flaw is triggered when Word processes a malicious RTF document, typically delivered as an email attachment or downloaded file; because Word also renders RTF content, simply opening or previewing attacker-supplied content can be enough to trigger it. Any user of an affected, unpatched Word installation who opens untrusted RTF documents is exposed; Microsoft shipped the fix in its December 2012 Word security bulletin (MS12-079). The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-28), confirming exploitation in the wild, and EPSS assigns a 53.2% probability of exploitation within 30 days (99th percentile), though no public PoC is known and ransomware use is unknown.
What to do: Apply the Microsoft Word security update from the December 2012 bulletin (MS12-079) on any Office install still in service, per CISA's required action to apply vendor updates. Until patched, do not open RTF documents from untrusted sources and confirm whether legacy 2012-era Word builds remain in use in your environment.
| Microsoft Word | Microsoft Word (affected version ranges not enumerated in source data; all Word builds supported by Microsoft at disclosure in 2012, fixed in the December 2012 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data.
- Affected
- Microsoft Word
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Microsoft
- Products
- Word
- Weakness
- CWE-399