cbcvebase.
CVE-2012-0158
published 2012-04-10

CVE-2012-0158: The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2…

PriorityP196high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
99.97%
100.0th percentile
The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and R2; BizTalk Server 2002 SP1; Commerce Server 2002 SP4, 2007 SP2, and 2009 Gold and R2; Visual FoxPro 8.0 SP1 and 9.0 SP2; and Visual Basic 6.0 Runtime allow remote attackers to execute arbitrary code via a crafted (a) web site, (b) Office document, or (c) .rtf file that triggers "system state" corruption, as exploited in the wild in April 2012, aka "MSCOMCTL.OCX RCE Vulnerability."

Affected

12 ranges
VendorProductVersion rangeFixed in
microsoftbiztalk_server
microsoftcommerce_server
microsoftcommerce_server
microsoftcommerce_server_2009
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice_web_components
microsoftsql_server_2008
microsoftvisual_basic
microsoftvisual_foxpro
microsoftvisual_foxpro

Detection & IOCsextracted from sources · hover to see the quote

hashb261f49fb6574af0bef16765c3db2900a5d3ca24639e9717bc21eb28e1e6be77
hashc982d2ab066c80f314af80dd5ba37ff9dd99288f
hash5beb50d95c1e720143ca0004f5172cb8881d75f6c9f434ceaff59f34fa1fe378
hash10090692ff40758a08bd66f806e0f2c831b4b9742bbf3d19c250e778de638f57
hash44dbf05bc81d17542a656525772e0f0973b603704f213278036d8ffc999bb79a
hash91ffe6fab7b33ff47b184b59356408951176c670cad3afcde79aa8464374acd3
hash6f3d4fb64de9ae61776fd19a8eba3d1d828e7e26bb89ace00c7843a57c5f6e8a
hashe88ea5eb642eaf832f8399d0337ba9eb1563862ddee68c26a74409a7384b9bb9
hash68f97bf3d03b1733944c25ff4933e4e03d973ccdd73d9528f4d68806b826735e
hash00ddae5bbc2ddf29954749519ecfb3978a68db6237ebea8e646a898c353053ce
hashc2ebaf4366835e16f34cc7f0b56f8eaf80a9818375c98672bc678bb4107b4d8c
hashaa86f4587423c2ff677aebae604614030f9f4d38280409501662ab4e4fe20c2a
hashfc21814a5f9ed2f6bef9e15b113d00f9291a6553c1e02cc0b4c185c6030eca45
other9368265E-85FE-11d1-8BE3-0000F8754DA1
domaindyn.kaleebso[.]com
domaindyn.pwnz[.]org
registrySOFTWARE\Microsoft\Windows\CurrentVersion\Run\Startup
path%TEMP%\~.dat
path%TEMP%\~.doc
commandcmd.exe /c dir /s %windir%\system32\*.sys&&taskkill /im winword.exe /f&dir /a /s %windir%\system32\*.msc && DOCUME~1\ADMINI~1\LOCALS~1\Temp\~.doc
filenamerundll32.exe
  • RTF exploit documents targeting CVE-2012-0158 can be detected by checking for invalid `listoverridecount` values in RTF; the only legal values are 0, 1, or 9 — other values indicate exploitation.
  • Snort rules 24974 and 24975 (referencing `listoverridecount`) provide coverage for RTF-based exploitation of this vulnerability family.
  • HOMEKit-generated malicious Word documents (OLE format) share consistent metadata: Author=User, Last Modified By=User, Company=HOME, Code Page=Windows Simplified Chinese, Create Date=2006:09:28 17:06:00, Modify Date=2006:09:28 17:09:00.
  • HOMEKit shellcode decryption stub uses ROR 3 combined with XOR key 0xAF on each ciphertext byte; this can be used as a static signature for HOMEKit shellcode.
  • Cookle Trojan uses a misspelled 'Cookie' HTTP header field in its C2 beacon containing the same value as its mutex (LDE_160425); hunt for HTTP requests with malformed Cookie headers matching this pattern.
  • Cookle Trojan uses a modified base64 encoding that swaps uppercase and lowercase letters in the base64 alphabet; this non-standard encoding can be used to fingerprint the malware's network traffic or strings.
  • Asruex variant drops and executes the infector as rundll32.exe from the Word document exploit; monitor for rundll32.exe being dropped to temp/working directories by Office processes.
  • Asruex anti-debugging check looks for avast! Sandbox path; presence of this check can be used to identify the malware family in memory or static analysis.
  • ·The Asruex variant only infects files within a specific size range; files outside this range are not targeted, which may limit detection coverage based on file size alone.
  • ·Cookle Trojan sleeps for 20 minutes before generating C2 beacons, which may cause sandbox analysis to miss network activity if analysis timeout is shorter than this delay.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.