CISA Known Exploited Vulnerability

CVE-2012-1856

Microsoft · Office

Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability

Date added
BOD 22-01 due date
CWE CWE-94
Ransomware Unknown

CISA description

The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption.

Required action

Apply updates per vendor instructions.