Vulnerability record · CVE-2012-1856 · published 15 August 2012
CVE-2012-1856: Microsoft Office MSCOMCTL.OCX TabStrip ActiveX Control Remote Code Execution
Microsoft · Commerce Server
The TabStrip ActiveX control in MSCOMCTL.OCX fails to properly handle system state, allowing a crafted document or web page to corrupt memory and execute arbitrary code. The flaw affects a wide range of Microsoft products that ship the Common Controls, including Office, SQL Server, Commerce Server, Host Integration Server, Visual FoxPro, and the Visual Basic 6.0 Runtime. Because the component is broadly deployed and the attack requires only that a user open a malicious file or visit a malicious page, it remains a serious risk for unpatched systems.
Description
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Server 2008 SP2, SP3, R2, R2 SP1, and R2 SP2, Commerce Server 2002 SP4, Commerce Server 2007 SP2, Commerce Server 2009 Gold and R2, Host Integration Server 2004 SP1, Visual FoxPro 8.0 SP1, Visual FoxPro 9.0 SP2, and Visual Basic 6.0 Runtime allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption, aka "MSCOMCTL.OCX RCE Vulnerability."
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe vulnerability is in CISA's Known Exploited Vulnerabilities catalog, has a very high EPSS score, and allows remote code execution with only user interaction across a wide range of widely deployed Microsoft products.
What it is
The TabStrip ActiveX control in MSCOMCTL.OCX fails to properly handle system state, allowing a crafted document or web page to corrupt memory and execute arbitrary code. The flaw affects a wide range of Microsoft products that ship the Common Controls, including Office, SQL Server, Commerce Server, Host Integration Server, Visual FoxPro, and the Visual Basic 6.0 Runtime. Because the component is broadly deployed and the attack requires only that a user open a malicious file or visit a malicious page, it remains a serious risk for unpatched systems.
Impact
An attacker can execute arbitrary code in the context of the user who opens the crafted document or visits the malicious web page. This can lead to full compromise of the affected host, including data theft, installation of malware, and lateral movement.
Attack surface
The vulnerability is reached over the network when a user opens a specially crafted document or views a malicious web page that instantiates the TabStrip ActiveX control. No authentication is required, but user interaction is necessary because the victim must open the file or visit the page.
Exploitation
CVE-2012-1856 is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. EPSS estimates a 72.2% probability of exploitation within 30 days, placing it in the 99.4th percentile, and the vendor advisory confirms a patch is available.
What to do
- Apply the Microsoft security update MS12-060 (or later cumulative updates) to all affected products immediately.
- Disable or remove the vulnerable TabStrip ActiveX control (COMCLT32.OCX / MSCOMCTL.OCX) where it is not required, using the kill-bit mechanism or Office Trust Center settings.
- Configure Office and Internet Explorer to block ActiveX controls and to prompt before running them, especially for untrusted documents and websites.
- Enforce the principle of least privilege so that users do not operate with administrative rights, limiting the impact of successful exploitation.
- Monitor for and restrict the opening of untrusted Office documents and web content from external sources.
Detection
- Hunt for processes that load MSCOMCTL.OCX or COMCLT32.OCX from unexpected locations or by non-Office applications.
- Monitor for Office applications (WINWORD.EXE, EXCEL.EXE, etc.) spawning child processes such as cmd.exe, powershell.exe, or wscript.exe, which may indicate exploitation.
- Review network and endpoint logs for known exploit delivery patterns, such as documents containing embedded ActiveX objects or referrals to malicious URLs.
- Use the CISA KEV catalog and vendor advisories to verify that all affected systems have been patched and to prioritize remediation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2012-1856 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/54948 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.us-cert.gov/cas/techalerts/TA12-227A.html | Third Party AdvisoryUS Government Resource |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-060 | PatchVendor Advisory |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15447 | Broken Link |
| http://www.securityfocus.com/bid/54948 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.us-cert.gov/cas/techalerts/TA12-227A.html | Third Party AdvisoryUS Government Resource |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-060 | PatchVendor Advisory |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15447 | Broken Link |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-1856 | US Government Resource |
Track CVE-2012-1856 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1856), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.