Netskope Threat Labs

FILE-OFFICE MSCOMCTL ActiveX control deserialization arbitrary code execution attempt

IPS-SWG

1 SID: 21797

First seen
February 2022
Last seen
October 2026

Detects a document exploiting CVE-2012-0158 through deserialized data in the Windows common controls ActiveX library, which can allow code execution without macros. The rule matches the crafted control class identifiers that public exploits use to reach the vulnerable deserialization path.