Stats
- First seen
- January 2022
- Last seen
- June 2026
Description
Detects a document exploiting CVE-2012-0158, the stack buffer overflow in the Windows common controls library that became one of the most reused targeted attack exploits. The rule matches the crafted control identifiers and stream structures that public exploits use to corrupt memory.