LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2012-2539: Microsoft Word Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 28, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 18, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2012-2539 to its Known Exploited Vulnerabilities catalog on Mar 28, 2022, with a federal patch deadline of Apr 18, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data.

CVE-2012-2539 is a remote code execution vulnerability in Microsoft Word that can also lead to denial-of-service. Attackers can trigger it by supplying crafted RTF data, which the application processes unsafely. For IT and security teams this matters because Word is widely deployed on endpoints and often opens documents from email or shared locations; successful abuse can give an attacker code execution in the context of the user or disrupt availability. Confirm all version and patch details against the vendor advisory.

How it works

The weakness is classified as CWE-399 (resource management errors). In this class of flaw, the application mishandles resources while parsing or rendering input, allowing an attacker to influence program state. According to the available summary, Microsoft Word processes crafted RTF data in a way that can result in remote code execution or a denial-of-service condition.

An attacker typically delivers a malicious RTF file—commonly via email attachment, file share, or download—and relies on the user opening it in Word (or an application that invokes Word’s RTF handling). Once processed, the flawed resource handling can be abused to run arbitrary code or crash the process. Exact exploit mechanics and memory-corruption details are not provided here; treat any public proof-of-concept claims cautiously and validate against the vendor advisory.

Am I affected? How to find it in your systems

Microsoft Word is the affected product. It commonly runs on Windows desktops and laptops used by knowledge workers, and may also appear in terminal-server or VDI environments. Inventory every system that has Microsoft Office or standalone Word installed.

If your inventory cannot confirm patch level, assume the host is potentially vulnerable until verified.

How to remediate

Patch first. Apply the updates Microsoft released for this vulnerability exactly as described in the vendor advisory and the CISA-required action: “Apply updates per vendor instructions.” Use your standard enterprise deployment channel (WSUS, Intune, ConfigMgr, or Microsoft Update) and verify successful installation on all affected endpoints.

If you can't patch immediately

When immediate patching is not possible, apply compensating controls to reduce exposure until the update can be installed.

These measures lower risk but do not replace the official update.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to endpoint compromise and subsequent data theft or ransomware, although ransomware use specifically tied to CVE-2012-2539 is not documented. If you have evidence of exploitation or suspect documents were opened on unpatched systems, follow your incident-response process: isolate affected hosts, collect forensic images, reset credentials, and hunt for persistence. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data to see whether associated credentials or personal information have appeared in prior breaches.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Word
WeaknessCWE-399
Added to CISA KEVMar 28, 2022
Federal patch deadlineApr 18, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities