Vulnerability record · CVE-2012-0182 · published 9 October 2012
CVE-2012-0182: Microsoft Word memory corruption in PAPX parsing enables code execution
Microsoft · Word
Microsoft Word 2007 SP2 and SP3 mishandles memory while parsing Word documents, a flaw Microsoft calls the Word PAPX Section Corruption Vulnerability. A crafted document can corrupt memory and lead to arbitrary code execution in the context of the user who opens it. The record does not state which specific memory operation fails or what the malformed PAPX data looks like.
Description
Microsoft Word 2007 SP2 and SP3 does not properly handle memory during the parsing of Word documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "Word PAPX Section Corruption Vulnerability."
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw allows remote code execution with no authentication and a high EPSS score, but exploitation requires the user to open a crafted document and there is no KEV or public exploit confirmation in the record.
What it is
Microsoft Word 2007 SP2 and SP3 mishandles memory while parsing Word documents, a flaw Microsoft calls the Word PAPX Section Corruption Vulnerability. A crafted document can corrupt memory and lead to arbitrary code execution in the context of the user who opens it. The record does not state which specific memory operation fails or what the malformed PAPX data looks like.
Impact
An attacker who gets a victim to open a malicious document can run arbitrary code with that user's privileges, giving full control of confidentiality, integrity and availability on the host. Because Word documents are routinely exchanged and trusted, a successful exploit can be used for initial access or lateral movement inside an organization.
Attack surface
Reached remotely over the network by delivering a crafted Word document, per the AV:N/AC:M/Au:N vector. No authentication is required, but exploitation depends on the victim opening the file, so user interaction is needed; the record does not specify whether preview panes or other automatic parsing paths also trigger it.
Exploitation
Not listed in CISA KEV and no reference carries an exploit tag, so there is no confirmed in-the-wild exploitation in this record. EPSS is high (0.683 probability over 30 days, 99.3rd percentile), indicating strong predicted likelihood of exploitation activity even without KEV confirmation.
What to do
- Apply Microsoft security bulletin MS12-064, which addresses this vulnerability, and confirm Word 2007 is at the fixed build.
- If Word 2007 cannot be patched promptly, restrict or block opening of untrusted Word documents and use a hardened viewer or conversion path instead.
- Enforce attachment filtering and mail gateway rules that strip or quarantine Word documents from external and unexpected senders.
- Run Word with reduced privileges and keep Microsoft Office file validation and Protected View enabled so malformed documents are caught before full parsing.
- Retire or upgrade Word 2007 where feasible, since it is long past end of support and no longer receives security fixes.
Detection
- Monitor for WINWORD.EXE spawning child processes such as cmd.exe, powershell.exe, wscript.exe or rundll32.exe, which is abnormal for document editing.
- Alert on Word crashing or restarting repeatedly for the same user or file, a common side effect of malformed document parsing.
- Hunt for Word documents written to temp or user directories immediately followed by process creation or outbound network connections from the Office process.
- Review endpoint telemetry for Office processes loading unusual modules or making network connections, and correlate with recently received email attachments.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-0182 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-0182), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.