Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability
Critical Listed in CISA KEV
Summary
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- Microsoft:Office
Sources
- CISA KEV DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2012-1856 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV