CVE-2012-1856
published 2012-08-15CVE-2012-1856: The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3…
PriorityP189high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
72.12%
99.4th percentile
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Server 2008 SP2, SP3, R2, R2 SP1, and R2 SP2, Commerce Server 2002 SP4, Commerce Server 2007 SP2, Commerce Server 2009 Gold and R2, Host Integration Server 2004 SP1, Visual FoxPro 8.0 SP1, Visual FoxPro 9.0 SP2, and Visual Basic 6.0 Runtime allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption, aka "MSCOMCTL.OCX RCE Vulnerability."
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | commerce_server | — | — |
| microsoft | commerce_server | — | — |
| microsoft | commerce_server | — | — |
| microsoft | host_integration_server | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office_web_components | — | — |
| microsoft | sql_server | — | — |
| microsoft | sql_server | — | — |
| microsoft | sql_server | — | — |
| microsoft | visual_basic | — | — |
| microsoft | visual_foxpro | — | — |
| microsoft | visual_foxpro | — | — |
Detection & IOCsextracted from sources · hover to see the quote
registryHKLM\Software\Microsoft\Windows\CurrentVersion\Run\update - %SYSTEM%\rundll32.exe %APPDATA\Intel\ResN32.dll Run↗
registryHKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs - %APPDATA%\Intel\ResN32.dll↗
- →CVE-2012-1856 exploitation is identified by the presence of CLSID 1EFB6596-857C-11D1-B16A-00C0F0283628 (MSCOMCTL TabStrip control) in ActiveX XML files embedded within weaponized RTF/OLE documents. ↗
- →T9000 malware dropped via CVE-2012-1856 RTF exploit stores all stage files under %APPDATA%\Intel\ directory; presence of this directory with files such as hccutils.dll, ResN32.dll, hjwe.dat, tyeu.dat, vnkd.dat, qhnj.dat is a strong post-exploitation indicator. ↗
- →T9000 checks HKLM\Software\ for 24 AV product registry keys to fingerprint the victim; monitoring for rapid sequential registry reads across these AV vendor keys from an Office process can indicate exploitation. ↗
- →Patchwork group weaponized RTF files exploiting CVE-2012-1856 (patched via MS12-060) to deliver the Badnews backdoor via DLL side-loading; RTF files with MSCOMCTL TabStrip ActiveX objects should be treated as high-risk. ↗
- →The Zyklon campaign uses TabStrip ActiveX controls (classid: {1EFB6596-857C-11D1-B16A-00C0F0283628}) for heap spraying in CVE-2013-3906 documents; the same CLSID is shared with CVE-2012-1856 exploitation and its presence in documents warrants scrutiny. ↗
- ·The mutex value for T9000 Stage 1 contains 'xx' placeholders, suggesting the source redacted portions of the actual mutex string; the full value may differ. ↗
- ·CVE-2012-1856 exploitation with the MSVCR71 ROP chain fails on 64-bit Office installations because msvcr71.dll is not present in the Office15 native add-ons folder, breaking hard-coded ROP gadget addresses. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q2jx-rgv9-xm3x: The TabStrip ActiveX control in the Common Controls in MSCOMCTL
ghsa_unreviewed·2022-05-14
CVE-2012-1856 [HIGH] CWE-94 GHSA-q2jx-rgv9-xm3x: The TabStrip ActiveX control in the Common Controls in MSCOMCTL
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Server 2008 SP2, SP3, R2, R2 SP1, and R2 SP2, Commerce Server 2002 SP4, Commerce Server 2007 SP2, Commerce Server 2009 Gold and R2, Host Integration Server 2004 SP1, Visual FoxPro 8.0 SP1, Visual FoxPro 9.0 SP2, and Visual Basic 6.0 Runtime allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption, aka "MSCOMCTL.OCX RCE Vulnerability."
VulnCheck
Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability
vulncheck·2012·CVSS 8.8
CVE-2012-1856 [HIGH] CWE-94 Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability
Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption.
Affected: Microsoft Office
Required Action: Apply updates per vendor instructions.
Exploitation References: https://securelist.com/the-icefog-apt-a-tale-of-cloak-and-three-daggers/57331/; https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/07205555/TheNaikonAPT-MsnMM1.pdf; https://cisa.gov/news-events/alerts/2015/04/29/top-30-targeted-high-risk-vulnerabilities; https://www.us-cert.gov/ncas/alerts/TA15-119A; https://documents.trendmicro.com/assets/tech-brief-untangling-the-patchwork-c
CISA
Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability
cisa·2022-03-03·CVSS 8.8
CVE-2012-1856 [HIGH] CWE-94 Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability
Vulnerability: Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability
Affected: Microsoft Office
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2012-1856
Remediation Due Date: 2022-03-24
No detection rules found.
No public exploits indexed.
arXiv
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
arxiv_fulltext·2025-02-12
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Almuthanna Alageel
and
Sergio Maffeis
Department of Computing
Imperial College London
London, United Kingdom
plain
plain
## Abstract
The scarcity of data and the high complexity of Advanced Persistent Threats (APTs) attacks have created challenges in comprehending their behavior and hindered the exploration of effective detection techniques.
To create an effective APT detection strategy, it is important to examine the Tactics, Techniques, and Procedures (TTPs) that have been reported by the industry. These TTPs can be difficult to classify as either malicious or legitimate. When developing an approach for the next generation of network intrusion detection systems (NIDS), it is necessary to
Unit42
Inception Attackers Target Europe with Year-old Office Vulnerability
blogs_unit42·2018-11-05·CVSS 8.8
CVE-2012-1856 [HIGH] Inception Attackers Target Europe with Year-old Office Vulnerability
Threat Research Center
Threat Research
Vulnerabilities
## Inception Attackers Target Europe with Year-old Office Vulnerability
Tom Lancaster
Published: November 5, 2018
Malware
Threat Research
Vulnerabilities
CVE-2012-1856
CVE-2017-11882
EMEA
Espionage
Government
Inception
PowerShell
PowerShower
Remote Templates
The Inception attackers have been active since at least 2014 and have been documented previously by both Blue Coat and Symantec ; historical attacks used custom malware for a variety of platforms, and targeting a range of industries, primarily in Russia, but also around the world. This blog describes attacks against European targets observed in October 2018, using CVE-2017-11882 and a new PowerShell backdoor we’re calling POWERSHOWER due to the attention to deta
Unit42
Inception Attackers Target Europe with Year-old Office Vulnerability
blogs_unit42·2018-11-05·CVSS 7.8
CVE-2017-11882 [HIGH] Inception Attackers Target Europe with Year-old Office Vulnerability
The Inception attackers have been active since at least 2014 and have been documented previously by both Blue Coat and Symantec; historical attacks used custom malware for a variety of platforms, and targeting a range of industries, primarily in Russia, but also around the world. This blog describes attacks against European targets observed in October 2018, using CVE-2017-11882 and a new PowerShell backdoor we’re calling POWERSHOWER due to the attention to detail in terms of cleaning up after itself, along with the malware being written in PowerShell.
Unit 42 has previously observed attacks from the group in 2017 against government targets in Europe, Russia, and Central Asia and expects these to remain the primary regions this threat is seen.
In the last writeup by Symantec they describe
Trendmicro
Untangling the Patchwork Cyberespionage Group
blogs_trendmicro·2017-12-11
Untangling the Patchwork Cyberespionage Group
Cyber Crime
# Untangling the Patchwork Cyberespionage Group
Patchwork (also known as Dropping Elephant) is a cyberespionage group known for targeting diplomatic and government agencies that has since added businesses to their list of targets.
By: Daniel Lunghi, Jaromir Horejsi, Cedric Pernet
2017/12/11
Read time: ( words)
Save to Folio
Updated as of October 9, 2018, 7:24PM PDT to remove Socksbot and update the appendix and technical brief; hat tip to Michael Yip of Accenture Security for an earlier research on Socksbot.
Patchwork (also known as Dropping Elephant) is a cyberespionage group known for targeting diplomatic and government agencies that has since added businesses to their list of targets. Patchwork’s moniker is from its notoriety for rehashing off-the-rack tools and malwa
Talos
Modified Zyklon and plugins from India
blogs_talos·2017-05-23·CVSS 8.8
[HIGH] Modified Zyklon and plugins from India
### Introduction Streams of malicious emails Talos inspects every day usually consist of active spamming campaigns for various ransomware families, phishing campaigns and the common malware family suspects such as banking Trojans and bots.. It is however often more interesting to analyze campaigns smaller in volume as they might contain more interesting malware. A few weeks ago I became interested in just such a campaign with a smaller number of circulating email messages. The email, first of them submitted from Middle East, purports to be coming from a Turkish trading company, which might further indicate the geographic area where the attacks were active. Analyzing malware is often like solving a puzzle, you have to do it piece by piece to reach the final image. In this case I spent more
Unit42
T9000: Advanced Modular Backdoor Uses Complex Anti-Analysis Techniques
blogs_unit42·2016-02-04
T9000: Advanced Modular Backdoor Uses Complex Anti-Analysis Techniques
Most custom backdoors used by advanced attackers have limited functionality. They evade detection by keeping their code simple and flying under the radar. But during a recent investigation we found a backdoor that takes a very different approach. We refer to this backdoor as T9000, which is a newer variant of the T5000 malware family, also known as Plat1.
In addition to the basic functionality all backdoors provide, T9000 allows the attacker to capture encrypted data, take screenshots of specific applications and specifically target Skype users. The malware goes to great lengths to identify a total of 24 potential security products that may be running on a system and customizes its installation mechanism to specifically evade those that are installed. It uses a multi-stage installation pr
Unit42
T9000: Advanced Modular Backdoor Uses Complex Anti-Analysis Techniques
blogs_unit42·2016-02-04
T9000: Advanced Modular Backdoor Uses Complex Anti-Analysis Techniques
## T9000: Advanced Modular Backdoor Uses Complex Anti-Analysis Techniques
Josh Grunzweig
Jen Miller-Osborn
Published: February 4, 2016
Malware
Threat Research
Skype
T5000
T9000
Trojans
Most custom backdoors used by advanced attackers have limited functionality. They evade detection by keeping their code simple and flying under the radar. But during a recent investigation we found a backdoor that takes a very different approach. We refer to this backdoor as T9000, which is a newer variant of the T5000 malware family, also known as Plat1.
In addition to the basic functionality all backdoors provide, T9000 allows the attacker to capture encrypted data, take screenshots of specific applications and specifically target Skype users. The malware goes to great lengths to identify a tot
Unit42
RTF Exploit Installs Italian RAT: uWarrior
blogs_unit42·2015-08-24·CVSS 8.8
CVE-2012-1856 [HIGH] RTF Exploit Installs Italian RAT: uWarrior
Unit 42 researchers have observed a new Remote Access Tool (RAT) constructed by an unknown actor of Italian origin. This RAT, referred to as uWarrior because of embedded PDB strings, has been previously described by an independent researcher who noted a potentially unknown exploit being used against Microsoft Office.
Initial research into the exploit by Unit 42 indicates that this actor has opted to include multiple exploits. One is CVE-2012-1856, reinvigorated with a novel ROP chain to bypass ASLR and deliver the uWarrior payload. The other appears to be CVE-2015-1770. The malware itself is a fully featured RAT, which uses a compressed, (optionally) encrypted, raw TCP socket and binary message protocol for command and control communications.
During the course of our research, it became
Unit42
RTF Exploit Installs Italian RAT: uWarrior
blogs_unit42·2015-08-24·CVSS 8.8
[HIGH] RTF Exploit Installs Italian RAT: uWarrior
## RTF Exploit Installs Italian RAT: uWarrior
Brandon Levene
Robert Falcone
Tomer Bar
Tom Keigher
Published: August 24, 2015
Malware
Threat Research
Remote Access Tool
UWarrior
Unit 42 researchers have observed a new Remote Access Tool (RAT) constructed by an unknown actor of Italian origin. This RAT, referred to as uWarrior because of embedded PDB strings, has been previously described by an independent researcher who noted a potentially unknown exploit being used against Microsoft Office.
Initial research into the exploit by Unit 42 indicates that this actor has opted to include multiple exploits. One is CVE-2012-1856, reinvigorated with a novel ROP chain to bypass ASLR and deliver the uWarrior payload. The other appears to be CVE-2015-1770. The malware itself is a fully feat
Threat Intel
Patchwork (Patchwork, Hangover Group, Dropping Elephant)
threat_intel
Patchwork (Patchwork, Hangover Group, Dropping Elephant)
# Threat Actor Profile: Patchwork
ATT&CK ID: G0040
Also known as: Patchwork, Hangover Group, Dropping Elephant, Chinastrats, MONSOON, Operation Hangover
Suspected origin: China
## Overview
Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or Indian entity. Patchwork has been seen targeting industries related to diplomatic and government agencies. Much of the code used by this group was copied and pasted from online forums. Patchwork was also seen operating spearphishing campaigns targeting U.S. think tank groups in March and April of 2018.(Citation: Cymmetria Patchwork) (Citation: Symantec Patchwork)(Citation: TrendMicro Patchwork Dec 2017)(Cita
Zscaler
Zscaler Protects against Microsoft's Patch Cycle | Round 6
blogs_zscaler·CVSS 9.3
[CRITICAL] Zscaler Protects against Microsoft's Patch Cycle | Round 6
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
http://www.securityfocus.com/bid/54948http://www.us-cert.gov/cas/techalerts/TA12-227A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-060https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15447http://www.securityfocus.com/bid/54948http://www.us-cert.gov/cas/techalerts/TA12-227A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-060https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15447https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-1856
2012-08-15
Published
2022-03-03
Added to CISA KEV
Exploited in the wild