← Back to CVE List
Vulnerability Intelligence Report
Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability

CVE-2012-1856

The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Server 2008 SP2, SP3, R2, R2 SP1, and R2 SP2, Commerce Server 2002 SP4, Commerce Server 2007 SP2, Commerce Server 2009 Gold and R2, Host Integration Server 2004 SP1, Visual FoxPro 8.0 SP1, Visual FoxPro 9.0 SP2, and Visual Basic 6.0 Runtime allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption, aka "MSCOMCTL.OCX RCE Vulnerability."

CISA KEV SSVC: Active Exploitation
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
EPSS Probability:72.12%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-94 ↗CWE-94 (via CISA KEV)

Affected Products & Versions

Vendor Product Affected Versions
microsoft commerce_server 2002, 2007, 2009
microsoft host_integration_server 2004
microsoft office 2003, 2007, 2010
microsoft office_web_components 2003
microsoft sql_server 2000, 2005, 2008
microsoft visual_basic 6.0
microsoft visual_foxpro 8.0, 9.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
72.119%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMicrosoft Corporation · Vendor · USA
Reserved2012-03-22T00:00:00
Published2012-08-15T01:00:00
Patch Date2012-08-14
Last Updated2025-10-22T00:05:46

LINK COPIED TO CLIPBOARD