9.3
CVE-2012-0158
- EPSS 99.97%
- Veröffentlicht 10.04.2012 21:55:01
- Zuletzt bearbeitet 16.06.2026 23:36:48
- Erkennungen
The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and R2; BizTalk Server 2002 SP1; Commerce Server 2002 SP4, 2007 SP2, and 2009 Gold and R2; Visual FoxPro 8.0 SP1 and 9.0 SP2; and Visual Basic 6.0 Runtime allow remote attackers to execute arbitrary code via a crafted (a) web site, (b) Office document, or (c) .rtf file that triggers "system state" corruption, as exploited in the wild in April 2012, aka "MSCOMCTL.OCX RCE Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Office Web Components Version 2003 Update sp3
Microsoft ≫ Sql Server 2000 Version - Update sp4
Microsoft ≫ Sql Server 2005 Version - Update sp4
Microsoft ≫ Sql Server 2008 Version - Update sp2
Microsoft ≫ Sql Server 2008 Version - Update sp3
Microsoft ≫ Sql Server 2008 Version r2 Update -
Microsoft ≫ Sql Server 2008 Version r2 Update sp1
Microsoft ≫ Biztalk Server Version 2002 Update sp1
Microsoft ≫ Commerce Server Version 2002 Update sp4
Microsoft ≫ Commerce Server Version 2007 Update sp2
Microsoft ≫ Commerce Server 2009 Version -
Microsoft ≫ Commerce Server 2009 Version r2
Microsoft ≫ Visual Basic Version 6.0
Microsoft ≫ Visual Foxpro Version 8.0 Update sp1
Microsoft ≫ Visual Foxpro Version 9.0 Update sp2
03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog
Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability
SchwachstelleMicrosoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current user.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 99.97% | 1 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| NIST | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
| CISA-ADP | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-94 Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
http://www.us-cert.gov/cas/techalerts/TA12-101A.html
http://opensources.info/comment-on-the-curious-case-of-a-cve-2012-0158-exploit-by-chris-pierce/
http://www.securityfocus.com/bid/52911
http://www.securitytracker.com/id?1026899
http://www.securitytracker.com/id?1026900
http://www.securitytracker.com/id?1026902
http://www.securitytracker.com/id?1026903
http://www.securitytracker.com/id?1026904
http://www.securitytracker.com/id?1026905
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-027
https://exchange.xforce.ibmcloud.com/vulnerabilities/74372
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15462
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-0158