← Vulnerability feed

Vulnerability record · CVE-2012-1856 · published 15 August 2012

CVE-2012-1856: Microsoft Office MSCOMCTL.OCX TabStrip ActiveX Control Remote Code Execution

Microsoft · Commerce Server

The TabStrip ActiveX control in MSCOMCTL.OCX fails to properly handle system state, allowing a crafted document or web page to corrupt memory and execute arbitrary code. The flaw affects a wide range of Microsoft products that ship the Common Controls, including Office, SQL Server, Commerce Server, Host Integration Server, Visual FoxPro, and the Visual Basic 6.0 Runtime. Because the component is broadly deployed and the attack requires only that a user open a malicious file or visit a malicious page, it remains a serious risk for unpatched systems.

8.8 CVSS 3.1 High CISA KEV since 3 Mar 2022 EPSS 72% · top 0.6%
8.8CVSS 3.1 base score, v2 9.3
72%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
7Affected product versions listed by NVD
9References
16 Jun 2026Last modified by NVD

Description

The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Server 2008 SP2, SP3, R2, R2 SP1, and R2 SP2, Commerce Server 2002 SP4, Commerce Server 2007 SP2, Commerce Server 2009 Gold and R2, Host Integration Server 2004 SP1, Visual FoxPro 8.0 SP1, Visual FoxPro 9.0 SP2, and Visual Basic 6.0 Runtime allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption, aka "MSCOMCTL.OCX RCE Vulnerability."

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe vulnerability is in CISA's Known Exploited Vulnerabilities catalog, has a very high EPSS score, and allows remote code execution with only user interaction across a wide range of widely deployed Microsoft products.

What it is

The TabStrip ActiveX control in MSCOMCTL.OCX fails to properly handle system state, allowing a crafted document or web page to corrupt memory and execute arbitrary code. The flaw affects a wide range of Microsoft products that ship the Common Controls, including Office, SQL Server, Commerce Server, Host Integration Server, Visual FoxPro, and the Visual Basic 6.0 Runtime. Because the component is broadly deployed and the attack requires only that a user open a malicious file or visit a malicious page, it remains a serious risk for unpatched systems.

Impact

An attacker can execute arbitrary code in the context of the user who opens the crafted document or visits the malicious web page. This can lead to full compromise of the affected host, including data theft, installation of malware, and lateral movement.

Attack surface

The vulnerability is reached over the network when a user opens a specially crafted document or views a malicious web page that instantiates the TabStrip ActiveX control. No authentication is required, but user interaction is necessary because the victim must open the file or visit the page.

Exploitation

CVE-2012-1856 is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. EPSS estimates a 72.2% probability of exploitation within 30 days, placing it in the 99.4th percentile, and the vendor advisory confirms a patch is available.

What to do

  • Apply the Microsoft security update MS12-060 (or later cumulative updates) to all affected products immediately.
  • Disable or remove the vulnerable TabStrip ActiveX control (COMCLT32.OCX / MSCOMCTL.OCX) where it is not required, using the kill-bit mechanism or Office Trust Center settings.
  • Configure Office and Internet Explorer to block ActiveX controls and to prompt before running them, especially for untrusted documents and websites.
  • Enforce the principle of least privilege so that users do not operate with administrative rights, limiting the impact of successful exploitation.
  • Monitor for and restrict the opening of untrusted Office documents and web content from external sources.

Detection

  • Hunt for processes that load MSCOMCTL.OCX or COMCLT32.OCX from unexpected locations or by non-Office applications.
  • Monitor for Office applications (WINWORD.EXE, EXCEL.EXE, etc.) spawning child processes such as cmd.exe, powershell.exe, or wscript.exe, which may indicate exploitation.
  • Review network and endpoint logs for known exploit delivery patterns, such as documents containing embedded ActiveX objects or referrals to malicious URLs.
  • Use the CISA KEV catalog and vendor advisories to verify that all affected systems have been patched and to prioritize remediation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2012-1856 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1856 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-23397Microsoft Outlook improper input validation privilege escalationCVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by cap…KEVEPSS 97%analysed8.8CVE-2023-35311Microsoft Outlook security feature bypass via TOCTOU race conditionCVE-2023-35311 is a security feature bypass in Microsoft Outlook caused by a time-of-check time-of-use (TOCTOU) race condition (CWE-367). It affects …KEVEPSS 16%analysed8.8CVE-2020-0618Microsoft SQL Server Reporting Services ViewState deserialization RCESQL Server Reporting Services mishandles page requests, allowing untrusted ViewState data to be deserialized (CWE-502). An authenticated attacker can…KEVEPSS 99%analysed8.8CVE-2019-1297Microsoft Excel memory handling flaw allows remote code executionCVE-2019-1297 is a remote code execution vulnerability in Microsoft Excel caused by improper handling of objects in memory. An attacker who convinces…KEVEPSS 22%analysed8.8CVE-2019-1068Microsoft SQL Server improper input validation remote code executionMicrosoft SQL Server mishandles processing of internal functions, allowing an authenticated remote attacker to execute code on the database server. T…KEVEPSS 58%analysed8.8CVE-2019-0541Microsoft MSHTML engine input validation flaw allows remote code executionThe MSHTML engine in Microsoft Office, Internet Explorer and related viewers fails to properly validate input, allowing remote code execution. Becaus…KEVEPSS 53%analysed8.8CVE-2018-0798Microsoft Office Equation Editor memory corruption RCEEquation Editor in Microsoft Office 2007 through 2016 mishandles objects in memory, producing an out-of-bounds write (CWE-787) that can be turned int…KEVEPSS 95%analysed8.8CVE-2015-2424Microsoft Office memory corruption via crafted documentCVE-2015-2424 is an out-of-bounds write (CWE-787) in Microsoft PowerPoint and Word that is triggered when a crafted Office document is opened. A remo…KEVEPSS 40%analysed

Source: NIST National Vulnerability Database (record CVE-2012-1856), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.