9.3

CVE-2012-0158

Warnung
The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and R2; BizTalk Server 2002 SP1; Commerce Server 2002 SP4, 2007 SP2, and 2009 Gold and R2; Visual FoxPro 8.0 SP1 and 9.0 SP2; and Visual Basic 6.0 Runtime allow remote attackers to execute arbitrary code via a crafted (a) web site, (b) Office document, or (c) .rtf file that triggers "system state" corruption, as exploited in the wild in April 2012, aka "MSCOMCTL.OCX RCE Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Office Version 2003 Update sp3
Microsoft ≫ Office Version 2007 Update sp2
Microsoft ≫ Office Version 2007 Update sp3
Microsoft ≫ Office Version 2010 Update - HwPlatform x86
Microsoft ≫ Office Version 2010 Update sp1 HwPlatform x86
Microsoft ≫ Office Web Components Version 2003 Update sp3
Microsoft ≫ Sql Server 2000 Version - Update sp4
Microsoft ≫ Sql Server 2005 Version - Update sp4
Microsoft ≫ Sql Server 2008 Version - Update sp2
Microsoft ≫ Sql Server 2008 Version - Update sp3
Microsoft ≫ Sql Server 2008 Version r2 Update -
Microsoft ≫ Sql Server 2008 Version r2 Update sp1
Microsoft ≫ Biztalk Server Version 2002 Update sp1
Microsoft ≫ Commerce Server Version 2002 Update sp4
Microsoft ≫ Commerce Server Version 2007 Update sp2
Microsoft ≫ Visual Basic Version 6.0
Microsoft ≫ Visual Foxpro Version 8.0 Update sp1
Microsoft ≫ Visual Foxpro Version 9.0 Update sp2

03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog

Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability

Schwachstelle

Microsoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current user.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 99.97% 1
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CISA-ADP 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

http://www.us-cert.gov/cas/techalerts/TA12-101A.html
Third Party Advisory
US Government Resource
http://opensources.info/comment-on-the-curious-case-of-a-cve-2012-0158-exploit-by-chris-pierce/
Broken Link
http://www.securityfocus.com/bid/52911
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id?1026899
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id?1026900
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id?1026902
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id?1026903
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id?1026904
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id?1026905
Third Party Advisory
Broken Link
VDB Entry
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-027
Patch
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/74372
Third Party Advisory
VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15462
Broken Link
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-0158
US Government Resource