CVE-2012-1856CISA KEVEPSS p99.4%

CVE-2012-1856Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability

Microsoft / Office

Description

The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption.

Scoring

EPSS72.12% probability of exploitation · percentile 99.4% · 2026-06-18T12:00:27Z

CISA KEV entry

Added to KEV: 2022-03-03

(incoming)1

TypeTargetConfidenceTier
KEVEntryMicrosoft Office MSCOMCTL.OCX Remote Code Execution Vulnerabilitykev-cve-2012-18560%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability
CVE
Microsoft Office Remote Code Execution Vulnerability
CVE
Microsoft Office Memory Corruption Vulnerability
CVE
Microsoft Office Remote Code Execution
CVE
Microsoft Word Remote Code Execution Vulnerability
CVE
Microsoft Office Stack-based Buffer Overflow Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.