Vulnerability record · CVE-2012-0013 · published 10 January 2012
CVE-2012-0013: Windows Packager blacklist bypass allows code execution via ClickOnce
Microsoft · Windows 7
The Windows Packager configuration in multiple legacy Windows versions uses an incomplete blacklist, so a crafted ClickOnce application embedded in a Microsoft Office document can bypass the intended restriction on .application files. Because the flaw leads to arbitrary code execution, it matters for any environment still running these unsupported platforms.
Description
Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted ClickOnce application in a Microsoft Office document, related to .application files, aka "Assembly Execution Vulnerability."
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution with no authentication required and a very high EPSS score, tempered by the need for user interaction and the age of the affected platforms.
What it is
The Windows Packager configuration in multiple legacy Windows versions uses an incomplete blacklist, so a crafted ClickOnce application embedded in a Microsoft Office document can bypass the intended restriction on .application files. Because the flaw leads to arbitrary code execution, it matters for any environment still running these unsupported platforms.
Impact
An attacker who gets the crafted document opened can execute arbitrary code with the privileges of the logged-on user, giving full control of confidentiality, integrity and availability on the host.
Attack surface
Reached remotely over the network by delivering a malicious Office document containing a crafted ClickOnce application; no authentication is required, but the victim must open the document, so user interaction is needed.
Exploitation
Not listed in CISA KEV and no reference carries an exploit tag, but EPSS is very high (0.73878, 99.455th percentile), indicating elevated predicted exploitation activity.
What to do
- Apply Microsoft security bulletin MS12-005 for the affected Windows versions as the primary fix.
- Disable or restrict the Windows Packager/ClickOnce handling of .application files where the patch cannot be applied.
- Block or strip .application and ClickOnce content from inbound Office documents at mail and web gateways.
- Upgrade or retire Windows XP, Server 2003, Vista, Server 2008 and Windows 7 Gold/SP1 systems that no longer receive support.
- Warn users not to open unexpected Office documents from untrusted senders.
Detection
- Monitor process creation spawned by Office applications, especially rundll32, dfshim or similar launching of .application content.
- Alert on Office documents containing embedded .application files or ClickOnce deployment manifests.
- Review proxy and mail logs for delivery of Office documents with ClickOnce payloads to internal users.
- Hunt for unexpected child processes or network callbacks originating from WINWORD.EXE, EXCEL.EXE or POWERPNT.EXE.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-0013 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-0013), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.