Home Microsoft CVE-2012-0158
CRITICAL: THIS VULNERABILITY IS ACTIVELY BEING EXPLOITED IN THE WILD (CISA KEV CATALOG)
Back to Microsoft

CVE-2012-0158

Exploited

Microsoft Office - MSCOMCTL.OCX

Microsoft CVSS 8.8 Updated April 30, 2026

Executive Risk Summary

"The MSCOMCTL.OCX ActiveX control in Microsoft Office is vulnerable to remote code execution, allowing an attacker to execute arbitrary code via a crafted web site, Office document, or .rtf file. This vulnerability can be exploited by an unauthenticated attacker, resulting in system state corruption and potential code execution."

Anticipated Attack Path

  1. 1. Initial Exploitation: Attacker crafts a malicious web site, Office document, or .rtf file
  2. 2. Vulnerability Exploitation: MSCOMCTL.OCX ActiveX control is triggered, causing system state corruption
  3. 3. Post-Exploitation: Attacker gains arbitrary code execution on the vulnerable system

Am I Vulnerable?

  • Verify Microsoft Office version and patch level
  • Check for presence of MSCOMCTL.OCX ActiveX control
  • Monitor system logs for suspicious activity

Operational Audit Arsenal

Target Type DLL
Target Asset MSCOMCTL.OCX
Standard Path C:\Windows\System32
PowerShell
# 🛠️ Senior Engineer Universal Audit
# Target: MSCOMCTL.OCX (DLL)
$Targets = 'MSCOMCTL.OCX'
$SearchPaths = @("$env:windir\System32", "$env:ProgramFiles", "${env:ProgramFiles(x86)}")

Get-ChildItem -Path $SearchPaths -Include $Targets -Recurse -ErrorAction SilentlyContinue | 
Select-Object FullName, @{Name="Version";Expression={$_.VersionInfo.ProductVersion}}

Patch Impact Forecast

Reboot Required Likely

Potential disruption to Microsoft Office functionality

Internal Work Notes

CVE-2012-0158: Microsoft Office MSCOMCTL.OCX RCE Vulnerability - Apply MS12-027 patch to vulnerable systems

Technical Intelligence & Operational Utilities • Delivered Weekly

Intelligence Sources

Official Advisoryhttp://opensources.info/comment-on-the-curious-case-of-a-cve-2012-0158-exploit-by-chris-pierce/
Official Advisoryhttp://www.securityfocus.com/bid/52911
Official Advisoryhttp://www.securitytracker.com/id?1026899
Official Advisoryhttp://www.securitytracker.com/id?1026900
Official Advisoryhttp://www.securitytracker.com/id?1026902
Official Advisoryhttp://www.securitytracker.com/id?1026903
Official Advisoryhttp://www.securitytracker.com/id?1026904
Official Advisoryhttp://www.securitytracker.com/id?1026905
Official Advisoryhttp://www.us-cert.gov/cas/techalerts/TA12-101A.html
MSRC Advisoryhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-027
Official Advisoryhttps://exchange.xforce.ibmcloud.com/vulnerabilities/74372
Official Advisoryhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15462
Official Advisoryhttp://opensources.info/comment-on-the-curious-case-of-a-cve-2012-0158-exploit-by-chris-pierce/
Official Advisoryhttp://www.securityfocus.com/bid/52911
Official Advisoryhttp://www.securitytracker.com/id?1026899
Official Advisoryhttp://www.securitytracker.com/id?1026900
Official Advisoryhttp://www.securitytracker.com/id?1026902
Official Advisoryhttp://www.securitytracker.com/id?1026903
Official Advisoryhttp://www.securitytracker.com/id?1026904
Official Advisoryhttp://www.securitytracker.com/id?1026905
Official Advisoryhttp://www.us-cert.gov/cas/techalerts/TA12-101A.html
MSRC Advisoryhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-027
Official Advisoryhttps://exchange.xforce.ibmcloud.com/vulnerabilities/74372
Official Advisoryhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15462
Official Advisoryhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-0158

Related Microsoft Threats

Data compiled from NVD, MSRC, and CISA KEV Catalog. Intelligence synthesized via AI. Scripts provided for diagnostic purposes under MIT License.