Microsoft Windows Common Control Library ActiveX Control
Microsoft Windows Common Control Library ActiveX Control Vulnerability
Release Date : 2012-04-10
Criticality level : Extremely critical
Impact : System access
Where : From remote
Solution Status : Vendor Patch
Software: Microsoft BizTalk Server 2002
Microsoft Commerce Server 2002
Microsoft Commerce Server 2007
Microsoft Commerce Server 2009
Microsoft Office 2003 Professional Edition
Microsoft Office 2003 Small Business Edition
Microsoft Office 2003 Standard Edition
Microsoft Office 2003 Student and Teacher Edition
Microsoft Office 2003 Web Components
Microsoft Office 2007
Microsoft Office 2010
Microsoft SQL Server 2000
Microsoft SQL Server 2000 Analysis Services
Microsoft SQL Server 2005
Microsoft SQL Server 2005 Express Edition
Microsoft SQL Server 2008
Microsoft Visual Basic 6.x
Microsoft Visual FoxPro 8.x
Microsoft Visual FoxPro 9.x
Description:
A vulnerability has been reported in some Microsoft products, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to an error within the MSCOMCTL.TreeView, MSCOMCTL.ListView2, MSCOMCTL.TreeView2, and MSCOMCTL.ListView controls (MSCOMCTL.OCX) and can be exploited to corrupt memory.
Successful exploitation allows execution of arbitrary code.
NOTE: This vulnerability is reportedly being actively exploited in targeted attacks.
Solution:
Apply updates.
Provided and/or discovered by:
Reported as a 0-day.
Original Advisory:
MS12-027 (KB2664258, KB2597112, KB2598041, KB2598039, KB983807, KB983808, KB983809, KB2645025, KB2658674, KB2658677, KB2655547, KB2658676, KB2647488, KB2647490, KB2641426):
http://technet.microsoft.com/en-us/security/bulletin/ms12-027
http://secunia.com/advisories/48786/
Was this reply helpful? (0) (0)
Staff pick