Vulnerability record · CVE-2012-0158 · published 10 April 2012
CVE-2012-0158: Microsoft MSCOMCTL.OCX ActiveX controls remote code execution
Microsoft · Office
The ListView, ListView2, TreeView and TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls fail to handle crafted input, allowing memory corruption that leads to arbitrary code execution. The flaw affects a wide range of Microsoft products that ship or embed the control, including Office, SQL Server, BizTalk Server, Commerce Server, Visual FoxPro and the Visual Basic 6.0 Runtime. It matters because it was exploited in the wild and remains in CISA's KEV catalog.
Description
The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and R2; BizTalk Server 2002 SP1; Commerce Server 2002 SP4, 2007 SP2, and 2009 Gold and R2; Visual FoxPro 8.0 SP1 and 9.0 SP2; and Visual Basic 6.0 Runtime allow remote attackers to execute arbitrary code via a crafted (a) web site, (b) Office document, or (c) .rtf file that triggers "system state" corruption, as exploited in the wild in April 2012, aka "MSCOMCTL.OCX RCE Vulnerability."
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is in CISA KEV with known ransomware use, has an extremely high EPSS score, and allows unauthenticated remote code execution with only user interaction.
What it is
The ListView, ListView2, TreeView and TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls fail to handle crafted input, allowing memory corruption that leads to arbitrary code execution. The flaw affects a wide range of Microsoft products that ship or embed the control, including Office, SQL Server, BizTalk Server, Commerce Server, Visual FoxPro and the Visual Basic 6.0 Runtime. It matters because it was exploited in the wild and remains in CISA's KEV catalog.
Impact
An attacker who gets the crafted content processed gains arbitrary code execution in the context of the victim user. That can mean full compromise of the user's data and credentials on the affected host.
Attack surface
Reachable remotely over the network via a crafted web site, Office document or .rtf file that instantiates the vulnerable ActiveX control. No authentication is required, but the CVSS vector (UI:R) indicates user interaction is needed, such as opening the document or visiting the page.
Exploitation
Listed in CISA KEV since 2021-11-03 with known ransomware campaign use, and EPSS is near the top of the scale (0.99976, 99.979th percentile). The description states it was exploited in the wild in April 2012.
What to do
- Apply the Microsoft update in security bulletin MS12-027 (KB2686509) to all affected products, prioritizing Office, SQL Server and the VB6 runtime.
- Remove or block the vulnerable MSCOMCTL.OCX ActiveX controls where they are not required, using the kill-bit guidance in MS12-027.
- Enforce Protected View and disable ActiveX in Office documents, and block untrusted .rtf and Office attachments at the mail and web gateways.
- Retire or isolate end-of-life platforms that cannot be patched, such as Office 2003, SQL Server 2000 and Visual FoxPro 8.0.
- Restrict outbound and inbound network access for hosts that still run these products to limit delivery of exploit documents.
Detection
- Hunt for Office, wscript, or browser processes loading MSCOMCTL.OCX and then spawning child processes such as cmd.exe, powershell.exe or rundll32.exe.
- Monitor for Office documents and .rtf files containing embedded ActiveX or OLE objects referencing MSCOMCTL.OCX ListView, ListView2, TreeView or TreeView2.
- Alert on crashes or heap corruption in MSCOMCTL.OCX reported by endpoint telemetry, especially clustered around document opens.
- Review proxy and mail logs for delivery of .rtf or Office attachments from untrusted senders to users on unpatched hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2012-0158 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-0158 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-0158), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.