← Vulnerability feed

Vulnerability record · CVE-2012-0182 · published 9 October 2012

CVE-2012-0182: Microsoft Word memory corruption in PAPX parsing enables code execution

Microsoft · Word

Microsoft Word 2007 SP2 and SP3 mishandles memory while parsing Word documents, a flaw Microsoft calls the Word PAPX Section Corruption Vulnerability. A crafted document can corrupt memory and lead to arbitrary code execution in the context of the user who opens it. The record does not state which specific memory operation fails or what the malformed PAPX data looks like.

9.3 CVSS 2.0 High EPSS 68% · top 0.7% CWE-94 · Code injection
9.3CVSS 2.0 base score
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Microsoft Word 2007 SP2 and SP3 does not properly handle memory during the parsing of Word documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "Word PAPX Section Corruption Vulnerability."

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe flaw allows remote code execution with no authentication and a high EPSS score, but exploitation requires the user to open a crafted document and there is no KEV or public exploit confirmation in the record.

What it is

Microsoft Word 2007 SP2 and SP3 mishandles memory while parsing Word documents, a flaw Microsoft calls the Word PAPX Section Corruption Vulnerability. A crafted document can corrupt memory and lead to arbitrary code execution in the context of the user who opens it. The record does not state which specific memory operation fails or what the malformed PAPX data looks like.

Impact

An attacker who gets a victim to open a malicious document can run arbitrary code with that user's privileges, giving full control of confidentiality, integrity and availability on the host. Because Word documents are routinely exchanged and trusted, a successful exploit can be used for initial access or lateral movement inside an organization.

Attack surface

Reached remotely over the network by delivering a crafted Word document, per the AV:N/AC:M/Au:N vector. No authentication is required, but exploitation depends on the victim opening the file, so user interaction is needed; the record does not specify whether preview panes or other automatic parsing paths also trigger it.

Exploitation

Not listed in CISA KEV and no reference carries an exploit tag, so there is no confirmed in-the-wild exploitation in this record. EPSS is high (0.683 probability over 30 days, 99.3rd percentile), indicating strong predicted likelihood of exploitation activity even without KEV confirmation.

What to do

  • Apply Microsoft security bulletin MS12-064, which addresses this vulnerability, and confirm Word 2007 is at the fixed build.
  • If Word 2007 cannot be patched promptly, restrict or block opening of untrusted Word documents and use a hardened viewer or conversion path instead.
  • Enforce attachment filtering and mail gateway rules that strip or quarantine Word documents from external and unexpected senders.
  • Run Word with reduced privileges and keep Microsoft Office file validation and Protected View enabled so malformed documents are caught before full parsing.
  • Retire or upgrade Word 2007 where feasible, since it is long past end of support and no longer receives security fixes.

Detection

  • Monitor for WINWORD.EXE spawning child processes such as cmd.exe, powershell.exe, wscript.exe or rundll32.exe, which is abnormal for document editing.
  • Alert on Word crashing or restarting repeatedly for the same user or file, a common side effect of malformed document parsing.
  • Hunt for Word documents written to temp or user directories immediately followed by process creation or outbound network connections from the Office process.
  • Review endpoint telemetry for Office processes loading unusual modules or making network connections, and correlate with recently received email attachments.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-0182 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2018-0798Microsoft Office Equation Editor memory corruption RCEEquation Editor in Microsoft Office 2007 through 2016 mishandles objects in memory, producing an out-of-bounds write (CWE-787) that can be turned int…KEVEPSS 95%analysed8.8CVE-2015-2424Microsoft Office memory corruption via crafted documentCVE-2015-2424 is an out-of-bounds write (CWE-787) in Microsoft PowerPoint and Word that is triggered when a crafted Office document is opened. A remo…KEVEPSS 40%analysed8.8CVE-2007-0671Microsoft Excel remote code execution via malformed fileCVE-2007-0671 is an unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, that allows re…KEVEPSS 43%analysed7.8CVE-2018-0802Microsoft Office Equation Editor Memory Corruption RCEEquation Editor in Microsoft Office 2007, 2010, 2013, and 2016 mishandles objects in memory, causing an out-of-bounds write (CWE-787) that can lead t…KEVEPSS 93%analysed7.8CVE-2017-11826Microsoft Office memory corruption allows remote code executionMicrosoft Office, Word, SharePoint, Office Web Apps and related products fail to properly handle objects in memory, a buffer overflow (CWE-119) that …KEVEPSS 81%analysed7.8CVE-2016-7193Microsoft Word RTF memory corruption allows remote code executionMicrosoft Word and related Office products mishandle a crafted RTF document, causing a memory corruption (buffer overflow) condition. Because the aff…KEVEPSS 58%analysed7.8CVE-2015-1641Microsoft Office Word RTF out-of-bounds write memory corruptionMicrosoft Word and related Office components (Word 2007/2010/2013, Word for Mac 2011, Office Compatibility Pack, Word Automation Services, Office Web…KEVEPSS 97%analysed7.8CVE-2014-1761Microsoft Word RTF memory corruption remote code executionMicrosoft Word and related Office components mishandle crafted RTF data, causing an out-of-bounds write (CWE-787) that corrupts memory. The flaw affe…KEVEPSS 77%analysed

Source: NIST National Vulnerability Database (record CVE-2012-0182), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.