Netskope Threat Labs

FILE-OFFICE Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt

IPS-SWG

1 SID: 31926

First seen
January 2022
Last seen
June 2026

Detects a document exploiting CVE-2012-0158, the stack buffer overflow in the Windows common controls library that became one of the most reused targeted attack exploits. The rule matches the crafted control identifiers and stream structures that public exploits use to corrupt memory.