Microsoft Windows Common Controls ActiveX Control CVE-2012-1856 Remote Code Execution Vulnerability
BID:54948
Info
Microsoft Windows Common Controls ActiveX Control CVE-2012-1856 Remote Code Execution Vulnerability
| Bugtraq ID: | 54948 |
| Class: | Design Error |
| CVE: |
CVE-2012-1856 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 14 2012 12:00AM |
| Updated: | Nov 07 2018 08:00AM |
| Credit: | Microsoft |
| Vulnerable: |
Microsoft Visual FoxPro 9.0 SP2 Microsoft Visual FoxPro 8.0 SP1 Microsoft Visual Basic 6.0 Runtime 0 Microsoft SQL Server 2008 x64 SP3 Microsoft SQL Server 2008 x64 SP2 Microsoft SQL Server 2008 x64 R2 Microsoft SQL Server 2008 itanium SP3 Microsoft SQL Server 2008 itanium SP2 Microsoft SQL Server 2008 itanium R2 Microsoft SQL Server 2008 32bit SP3 Microsoft SQL Server 2008 32bit SP2 Microsoft SQL Server 2008 32bit R2 Microsoft SQL Server 2008 R2 SP1 Microsoft SQL Server 2008 R2 Microsoft SQL Server 2005 x64 Edition SP4 Microsoft SQL Server 2005 Itanium Edition SP4 Microsoft SQL Server 2005 Express Edition with Advanced Serv SP4 Microsoft SQL Server 2005 Express Edition with Advanced Serv SP3 Microsoft SQL Server 2005 Express Edition with Advanced Serv SP2 Microsoft SQL Server 2005 Express Edition with Advanced Serv SP1 Microsoft SQL Server 2005 SP4 Microsoft SQL Server 2000 Analysis Services SP4 0 Microsoft SQL Server 2000 SP4 Microsoft Office 2010 (32-bit edition) SP1 Microsoft Office 2007 SP3 Microsoft Office 2007 SP2 Microsoft Office 2003 Web Components SP3 Microsoft Office 2003 SP3 Microsoft Host Integration Server 2004 SP1 Microsoft Commerce Server 2009 R2 Microsoft Commerce Server 2009 0 Microsoft Commerce Server 2007 SP2 Microsoft Commerce Server 2002 SP4 Microsoft BizTalk Server 2002 SP1 |
| Not Vulnerable: | |
Discussion
Microsoft Windows Common Controls ActiveX Control CVE-2012-1856 Remote Code Execution Vulnerability
Microsoft Windows Common Controls is prone to a remote code-execution vulnerability.
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious webpage.
Successful exploits will allow the attacker to execute arbitrary code within the context of the application (typically Internet Explorer) that uses the ActiveX control.
Microsoft Windows Common Controls is prone to a remote code-execution vulnerability.
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious webpage.
Successful exploits will allow the attacker to execute arbitrary code within the context of the application (typically Internet Explorer) that uses the ActiveX control.
Exploit / POC
Microsoft Windows Common Controls ActiveX Control CVE-2012-1856 Remote Code Execution Vulnerability
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service.
Microsoft has reported that this issue is being exploited in the wild in limited and targeted attacks.
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service.
Microsoft has reported that this issue is being exploited in the wild in limited and targeted attacks.
Solution / Fix
Microsoft Windows Common Controls ActiveX Control CVE-2012-1856 Remote Code Execution Vulnerability
Solution:
The vendor released an advisory and updates. Please see the references for details.
Microsoft Office 2003 Web Components SP3
Microsoft Office 2003 SP3
Microsoft Office 2007 SP3
Microsoft Office 2007 SP2
Microsoft Office 2010 (32-bit edition) SP1
Solution:
The vendor released an advisory and updates. Please see the references for details.
Microsoft Office 2003 Web Components SP3
-
Microsoft Security Update for Microsoft Office 2003 (KB2687323)
http://www.microsoft.com/downloads/details.aspx?FamilyId=f22593be-d0b6 -4b83-b0d6-d872d88241b3
Microsoft Office 2003 SP3
-
Microsoft Security Update for Microsoft Office 2003 (KB2687323)
http://www.microsoft.com/downloads/details.aspx?FamilyId=f22593be-d0b6 -4b83-b0d6-d872d88241b3
Microsoft Office 2007 SP3
-
Microsoft Security Update for Microsoft Office 2007 suites (KB2687441)
http://www.microsoft.com/downloads/details.aspx?FamilyId=b1c185e9-5328 -4bf7-b175-fd9d7fc64097
Microsoft Office 2007 SP2
-
Microsoft Security Update for Microsoft Office 2007 suites (KB2687441)
http://www.microsoft.com/downloads/details.aspx?FamilyId=b1c185e9-5328 -4bf7-b175-fd9d7fc64097
Microsoft Office 2010 (32-bit edition) SP1
-
Microsoft Security Update for Microsoft Office 2010 (KB2597986) 32-Bit Edition
http://www.microsoft.com/downloads/details.aspx?FamilyId=4e08bab7-1408 -444d-bad7-a4db76c7f6d3
References
Microsoft Windows Common Controls ActiveX Control CVE-2012-1856 Remote Code Execution Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- VUPEN Security Research - Microsoft Windows Common Controls MSCOMCTL.OCX Use-aft (Nicolas Joly)
- Microsoft Security Bulletin MS12-060 (Microsoft)
- MS12-060: Addressing a vulnerability in MSCOMCTL.OCX's TabStrip control (Microsoft)