CVE-2012-1856CISA KEV
Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption.
- Product
- Office
- Added to KEV
- 3 Mar 2022
- Federal remediation due
- 24 Mar 2022
- Known ransomware use
- Not reported