← Vulnerability feed

Vulnerability record · CVE-2012-0158 · published 10 April 2012

CVE-2012-0158: Microsoft MSCOMCTL.OCX ActiveX controls remote code execution

Microsoft · Office

The ListView, ListView2, TreeView and TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls fail to handle crafted input, allowing memory corruption that leads to arbitrary code execution. The flaw affects a wide range of Microsoft products that ship or embed the control, including Office, SQL Server, BizTalk Server, Commerce Server, Visual FoxPro and the Visual Basic 6.0 Runtime. It matters because it was exploited in the wild and remains in CISA's KEV catalog.

8.8 CVSS 3.1 High CISA KEV since 3 Nov 2021 Known ransomware use EPSS 100% · top 0.1% CWE-94 · Code injection
8.8CVSS 3.1 base score, v2 9.3
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
10Affected product versions listed by NVD
25References
16 Jun 2026Last modified by NVD

Description

The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and R2; BizTalk Server 2002 SP1; Commerce Server 2002 SP4, 2007 SP2, and 2009 Gold and R2; Visual FoxPro 8.0 SP1 and 9.0 SP2; and Visual Basic 6.0 Runtime allow remote attackers to execute arbitrary code via a crafted (a) web site, (b) Office document, or (c) .rtf file that triggers "system state" corruption, as exploited in the wild in April 2012, aka "MSCOMCTL.OCX RCE Vulnerability."

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with known ransomware use, has an extremely high EPSS score, and allows unauthenticated remote code execution with only user interaction.

What it is

The ListView, ListView2, TreeView and TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls fail to handle crafted input, allowing memory corruption that leads to arbitrary code execution. The flaw affects a wide range of Microsoft products that ship or embed the control, including Office, SQL Server, BizTalk Server, Commerce Server, Visual FoxPro and the Visual Basic 6.0 Runtime. It matters because it was exploited in the wild and remains in CISA's KEV catalog.

Impact

An attacker who gets the crafted content processed gains arbitrary code execution in the context of the victim user. That can mean full compromise of the user's data and credentials on the affected host.

Attack surface

Reachable remotely over the network via a crafted web site, Office document or .rtf file that instantiates the vulnerable ActiveX control. No authentication is required, but the CVSS vector (UI:R) indicates user interaction is needed, such as opening the document or visiting the page.

Exploitation

Listed in CISA KEV since 2021-11-03 with known ransomware campaign use, and EPSS is near the top of the scale (0.99976, 99.979th percentile). The description states it was exploited in the wild in April 2012.

What to do

  • Apply the Microsoft update in security bulletin MS12-027 (KB2686509) to all affected products, prioritizing Office, SQL Server and the VB6 runtime.
  • Remove or block the vulnerable MSCOMCTL.OCX ActiveX controls where they are not required, using the kill-bit guidance in MS12-027.
  • Enforce Protected View and disable ActiveX in Office documents, and block untrusted .rtf and Office attachments at the mail and web gateways.
  • Retire or isolate end-of-life platforms that cannot be patched, such as Office 2003, SQL Server 2000 and Visual FoxPro 8.0.
  • Restrict outbound and inbound network access for hosts that still run these products to limit delivery of exploit documents.

Detection

  • Hunt for Office, wscript, or browser processes loading MSCOMCTL.OCX and then spawning child processes such as cmd.exe, powershell.exe or rundll32.exe.
  • Monitor for Office documents and .rtf files containing embedded ActiveX or OLE objects referencing MSCOMCTL.OCX ListView, ListView2, TreeView or TreeView2.
  • Alert on crashes or heap corruption in MSCOMCTL.OCX reported by endpoint telemetry, especially clustered around document opens.
  • Review proxy and mail logs for delivery of .rtf or Office attachments from untrusted senders to users on unpatched hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2012-0158 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://opensources.info/comment-on-the-curious-case-of-a-cve-2012-0158-exploit-by-chris-pierce/ Broken Link
http://www.securityfocus.com/bid/52911 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1026899 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1026900 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1026902 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1026903 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1026904 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1026905 Broken LinkThird Party AdvisoryVDB Entry
http://www.us-cert.gov/cas/techalerts/TA12-101A.html Third Party AdvisoryUS Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-027 PatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/74372 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15462 Broken Link
http://opensources.info/comment-on-the-curious-case-of-a-cve-2012-0158-exploit-by-chris-pierce/ Broken Link
http://www.securityfocus.com/bid/52911 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1026899 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1026900 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1026902 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1026903 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1026904 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1026905 Broken LinkThird Party AdvisoryVDB Entry
http://www.us-cert.gov/cas/techalerts/TA12-101A.html Third Party AdvisoryUS Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-027 PatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/74372 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15462 Broken Link
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-0158 US Government Resource

Track CVE-2012-0158 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-23397Microsoft Outlook improper input validation privilege escalationCVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by cap…KEVEPSS 97%analysed8.8CVE-2023-35311Microsoft Outlook security feature bypass via TOCTOU race conditionCVE-2023-35311 is a security feature bypass in Microsoft Outlook caused by a time-of-check time-of-use (TOCTOU) race condition (CWE-367). It affects …KEVEPSS 16%analysed8.8CVE-2019-1297Microsoft Excel memory handling flaw allows remote code executionCVE-2019-1297 is a remote code execution vulnerability in Microsoft Excel caused by improper handling of objects in memory. An attacker who convinces…KEVEPSS 22%analysed8.8CVE-2019-0541Microsoft MSHTML engine input validation flaw allows remote code executionThe MSHTML engine in Microsoft Office, Internet Explorer and related viewers fails to properly validate input, allowing remote code execution. Becaus…KEVEPSS 53%analysed8.8CVE-2018-0798Microsoft Office Equation Editor memory corruption RCEEquation Editor in Microsoft Office 2007 through 2016 mishandles objects in memory, producing an out-of-bounds write (CWE-787) that can be turned int…KEVEPSS 95%analysed8.8CVE-2015-2424Microsoft Office memory corruption via crafted documentCVE-2015-2424 is an out-of-bounds write (CWE-787) in Microsoft PowerPoint and Word that is triggered when a crafted Office document is opened. A remo…KEVEPSS 40%analysed8.8CVE-2015-1770Microsoft Office uninitialized memory use allows remote code executionMicrosoft Office 2013 SP1 and 2013 RT SP1 mishandle uninitialized memory when parsing a crafted Office document, which can lead to arbitrary code exe…KEVEPSS 35%analysed8.8CVE-2012-1856Microsoft Office MSCOMCTL.OCX TabStrip ActiveX Control Remote Code ExecutionThe TabStrip ActiveX control in MSCOMCTL.OCX fails to properly handle system state, allowing a crafted document or web page to corrupt memory and exe…KEVEPSS 72%analysed

Source: NIST National Vulnerability Database (record CVE-2012-0158), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.