LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2012-0158: Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2012-0158 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current…

CVE-2012-0158 is a remote code execution vulnerability in Microsoft MSCOMCTL.OCX, a common controls library used by Microsoft Office and other Windows applications. An attacker who successfully exploits it can run code in the context of the current user and potentially take full control of the affected system. For IT and security teams, this matters because the component is widely present on Windows desktops and can be reached through everyday document or application workflows, making prompt inventory and patching essential.

How it works

The weakness is classified as CWE-94 (code injection). In broad terms for this class, the vulnerable library fails to safely handle certain input, allowing crafted data to influence code execution paths inside the process that loads MSCOMCTL.OCX. An attacker typically delivers a specially crafted file or content that causes the host application to load the vulnerable control; when the flawed parsing or handling occurs, the attacker’s code can run with the privileges of the logged-on user. Public detail on exact exploit mechanics is limited; treat any observed attack patterns as consistent with remote code execution against this component and confirm technical specifics against the vendor advisory.

Am I affected? How to find it in your systems

MSCOMCTL.OCX is a Microsoft common-controls ActiveX/OCX component historically used by Office and other Windows applications that embed list-view, tree-view, and similar UI controls. It typically appears on Windows endpoints where Microsoft Office or legacy applications that depend on these controls are installed.

How to remediate

Patch first. Apply the Microsoft updates that remediate CVE-2012-0158 exactly as directed in the vendor advisory and CISA’s required action to apply updates per vendor instructions. After deployment, verify that the vulnerable MSCOMCTL.OCX binary has been replaced by the fixed version across the estate.

If you can't patch immediately

Until the vendor update can be applied everywhere, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited remote code execution vulnerabilities can lead to account takeover, malware installation, and data theft under the user’s context. Known ransomware use is not documented for this CVE, but any confirmed compromise should be handled through standard incident response: isolate affected hosts, reset credentials, and review for persistence and data access. You can run a free exposure scan of your email addresses against known breach data to check whether associated accounts appear in public breach corpora and then prioritize password changes and monitoring accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · MSCOMCTL.OCX
WeaknessCWE-94
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities