EXPOSURES › CVE-2012-1856
CVE-2012-1856
HIGH ⌖ ON CISA KEV · EXPLOITEDA 12-year-old unpatched Microsoft Office ActiveX vulnerability in MSCOMCTL.OCX allows remote attackers to execute arbitrary code via crafted documents or web pages.
This long-standing unpatched vulnerability in Microsoft Office's MSCOMCTL.OCX component enables remote code execution through malicious documents or web pages, directly impacting DIB organizations reliant on Office for daily operations. The fact that it remained unpatched for over a decade demonstrates severe negligence in patch management and software lifecycle oversight. DIBs must rigorously validate their patching cadences and assume that legacy components in widely deployed software can be actively exploited in the wild.
Shame score — A critical remote code execution flaw remained unpatched for over a decade, representing extreme negligence and a massive, avoidable security gap that was eventually added to the KEV catalog.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |