cbcvebase.
CVE-2012-1856
published 2012-08-15

CVE-2012-1856: The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3…

PriorityP189high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
72.12%
99.4th percentile
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Server 2008 SP2, SP3, R2, R2 SP1, and R2 SP2, Commerce Server 2002 SP4, Commerce Server 2007 SP2, Commerce Server 2009 Gold and R2, Host Integration Server 2004 SP1, Visual FoxPro 8.0 SP1, Visual FoxPro 9.0 SP2, and Visual Basic 6.0 Runtime allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption, aka "MSCOMCTL.OCX RCE Vulnerability."

Affected

14 ranges
VendorProductVersion rangeFixed in
microsoftcommerce_server
microsoftcommerce_server
microsoftcommerce_server
microsofthost_integration_server
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice_web_components
microsoftsql_server
microsoftsql_server
microsoftsql_server
microsoftvisual_basic
microsoftvisual_foxpro
microsoftvisual_foxpro

Detection & IOCsextracted from sources · hover to see the quote

other1EFB6596-857C-11D1-B16A-00C0F0283628
hash7ff9ff29b79d0eb38813bfa0b0bb1c5b116d1f9e5468ae52674bb443468658d9
hash7f29f2dc8b60c0e5a22575d9c76fd9c3d39604d1acf5cb4d938a63095c61a72e
hashfe80d59686806afe3dc48f73d54b577558a7c871da17d08d937c5d7b3564e07b
hash70ea7ef3bf9966c3297a4e78024e3083013558670d051c2ca3095e2588a576d8
path%TEMP%\~tmp.doc
commandcmd /C %TEMP%\~tmp.doc
mutex820C90CxxA1B084495866C6D95B2595xx1C3
mutexGlobal\\deletethread
registryHKLM\Software\Microsoft\Windows\CurrentVersion\Run\Eupdate - %APPDATA%\Intel\ResN32.dll
registryHKLM\Software\Microsoft\Windows\CurrentVersion\Run\update - %SYSTEM%\rundll32.exe %APPDATA\Intel\ResN32.dll Run
registryHKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs - %APPDATA%\Intel\ResN32.dll
registryHKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\LoadAppInit_DLLs – 0x1
path%APPDATA%\Intel\avinfo
filenamehccutils.dll
filenameResN32.dll
filenameQQMgr.dll
  • CVE-2012-1856 exploitation is identified by the presence of CLSID 1EFB6596-857C-11D1-B16A-00C0F0283628 (MSCOMCTL TabStrip control) in ActiveX XML files embedded within weaponized RTF/OLE documents.
  • T9000 malware dropped via CVE-2012-1856 RTF exploit stores all stage files under %APPDATA%\Intel\ directory; presence of this directory with files such as hccutils.dll, ResN32.dll, hjwe.dat, tyeu.dat, vnkd.dat, qhnj.dat is a strong post-exploitation indicator.
  • T9000 checks HKLM\Software\ for 24 AV product registry keys to fingerprint the victim; monitoring for rapid sequential registry reads across these AV vendor keys from an Office process can indicate exploitation.
  • Patchwork group weaponized RTF files exploiting CVE-2012-1856 (patched via MS12-060) to deliver the Badnews backdoor via DLL side-loading; RTF files with MSCOMCTL TabStrip ActiveX objects should be treated as high-risk.
  • The Zyklon campaign uses TabStrip ActiveX controls (classid: {1EFB6596-857C-11D1-B16A-00C0F0283628}) for heap spraying in CVE-2013-3906 documents; the same CLSID is shared with CVE-2012-1856 exploitation and its presence in documents warrants scrutiny.
  • ·The mutex value for T9000 Stage 1 contains 'xx' placeholders, suggesting the source redacted portions of the actual mutex string; the full value may differ.
  • ·CVE-2012-1856 exploitation with the MSVCR71 ROP chain fails on 64-bit Office installations because msvcr71.dll is not present in the Office15 native add-ons folder, breaking hard-coded ROP gadget addresses.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.