CVE-2012-0158

Scores

EPSS

0.943High94.3%
0%20%40%60%80%100%

Percentile: 94.3%

CVSS

8.8High3.x
0246810

CVSS Score: 8.8/10

All CVSS Scores

CVSS 3.x
8.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS 2.0
9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Description

The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and R2; BizTalk Server 2002 SP1; Commerce Server 2002 SP4, 2007 SP2, and 2009 Gold and R2; Visual FoxPro 8.0 SP1 and 9.0 SP2; and Visual Basic 6.0 Runtime allow remote attackers to execute arbitrary code via a crafted (a) web site, (b) Office document, or © .rtf file that triggers “system state” corruption, as exploited in the wild in April 2012, aka “MSCOMCTL.OCX RCE Vulnerability.”

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-94

Related Vulnerabilities

Exploits

Exploit ID: CVE-2012-0158

Source: cisa

URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

Exploit ID: 18780

Source: exploitdb

URL: https://www.exploit-db.com/exploits/18780

Vulnerable Software (10)

Type: Configuration

Vendor: microsoft

Product: biztalk_server

Operating System: * * *

Trait:
{
  "cpe_match": [
    {
      "cpe23uri": "cpe:2.3:a:microsoft:biztalk_server:2002:sp1:*:*:*:*:*:*",
      "vulnerable": true
    },
    {
      "cpe23uri": "cpe:2.3:a:microsoft:commerce_server:2002:...

Source: nvd

Type: Configuration

Vendor: microsoft

Product: commerce_server

Operating System: * * *

Trait:
{
  "cpe_match": [
    {
      "cpe23uri": "cpe:2.3:a:microsoft:biztalk_server:2002:sp1:*:*:*:*:*:*",
      "vulnerable": true
    },
    {
      "cpe23uri": "cpe:2.3:a:microsoft:commerce_server:2002:...

Source: nvd

Type: Configuration

Vendor: microsoft

Product: commerce_server_2009

Operating System: * * *

Trait:
{
  "cpe_match": [
    {
      "cpe23uri": "cpe:2.3:a:microsoft:biztalk_server:2002:sp1:*:*:*:*:*:*",
      "vulnerable": true
    },
    {
      "cpe23uri": "cpe:2.3:a:microsoft:commerce_server:2002:...

Source: nvd

Type: Configuration

Vendor: microsoft

Product: office

Operating System: * * *

Trait:
{
  "cpe_match": [
    {
      "cpe23uri": "cpe:2.3:a:microsoft:office:2003:sp3:*:*:*:*:*:*",
      "vulnerable": true
    },
    {
      "cpe23uri": "cpe:2.3:a:microsoft:office:2007:sp2:*:*:*:*:*:*",...

Source: nvd

Type: Configuration

Vendor: microsoft

Product: office_web_components

Operating System: * * *

Trait:
{
  "cpe_match": [
    {
      "cpe23uri": "cpe:2.3:a:microsoft:office:2003:sp3:*:*:*:*:*:*",
      "vulnerable": true
    },
    {
      "cpe23uri": "cpe:2.3:a:microsoft:office:2007:sp2:*:*:*:*:*:*",...

Source: nvd

Type: Configuration

Vendor: microsoft

Product: sql_server_2000

Operating System: * * *

Trait:
{
  "cpe_match": [
    {
      "cpe23uri": "cpe:2.3:a:microsoft:sql_server_2000:-:sp4:*:*:*:*:*:*",
      "vulnerable": true
    },
    {
      "cpe23uri": "cpe:2.3:a:microsoft:sql_server_2005:-:sp4:*...

Source: nvd

Type: Configuration

Vendor: microsoft

Product: sql_server_2005

Operating System: * * *

Trait:
{
  "cpe_match": [
    {
      "cpe23uri": "cpe:2.3:a:microsoft:sql_server_2000:-:sp4:*:*:*:*:*:*",
      "vulnerable": true
    },
    {
      "cpe23uri": "cpe:2.3:a:microsoft:sql_server_2005:-:sp4:*...

Source: nvd

Type: Configuration

Vendor: microsoft

Product: sql_server_2008

Operating System: * * *

Trait:
{
  "cpe_match": [
    {
      "cpe23uri": "cpe:2.3:a:microsoft:sql_server_2000:-:sp4:*:*:*:*:*:*",
      "vulnerable": true
    },
    {
      "cpe23uri": "cpe:2.3:a:microsoft:sql_server_2005:-:sp4:*...

Source: nvd

Type: Configuration

Vendor: microsoft

Product: visual_basic

Operating System: * * *

Trait:
{
  "cpe_match": [
    {
      "cpe23uri": "cpe:2.3:a:microsoft:visual_basic:6.0:*:*:*:*:*:*:*",
      "vulnerable": true
    },
    {
      "cpe23uri": "cpe:2.3:a:microsoft:visual_foxpro:8.0:sp1:*:*:...

Source: nvd

Type: Configuration

Vendor: microsoft

Product: visual_foxpro

Operating System: * * *

Trait:
{
  "cpe_match": [
    {
      "cpe23uri": "cpe:2.3:a:microsoft:visual_basic:6.0:*:*:*:*:*:*:*",
      "vulnerable": true
    },
    {
      "cpe23uri": "cpe:2.3:a:microsoft:visual_foxpro:8.0:sp1:*:*:...

Source: nvd