← Back to browse · API

CVE-2012-1856

Severity
HIGH
CVSS
8.8
EPSS
0.61826
Risk score
81.84
CISA KEV
Yes
PoC
No
Published
2022-03-03
Modified
2022-03-03
First seen
2026-08-07
Aliases
EUVD-2012-1866, GHSA-Q2JX-RGV9-XM3X
Products
Microsoft:Office, n/a:n/a n/a
Sources
euvd EUVD-2012-1866
cisa.gov CVE-2012-1856

Description

The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption.

References