Skip to content

Davey Winder

delivering award-winning technology journalism since 1991

  • home
  • about me
  • follow me on mastodon
  • privacy policy
  • Toggle search form
x-ray image of a zombie

CVE-ZOMBIE: the Word vulnerability that refuses to die

Posted on July 7, 2016July 7, 2016 By Davey Winder

So CVE-2012-0158 was allocated in 2011, patched in 2012 and is being actively exploited in 2016: the question is why?

If a vulnerability was allocated a CVE number in 2011, and a patch released in 2012, you’d expect it to be long dead. So why is CVE-2012-0158 not only still alive, but still eating virtual brains? In his research paper ‘Anatomy of a prolific exploit’ Sophos researcher Graham Chantry states “Whether you’re an experienced threat researcher, a keen security blog reader or you’ve simply received a malicious Office document attachment; you’ll have likely come across the CVE-2012-0158 vulnerability in some form.” And he’s not wrong.

Not only is this particular MS Word vulnerability far from dead, it remains one of the most actively exploited vulnerabilities across the Word family. Which begs the question, what has gone so right for the bad guys and what’s so special about CVE-2012-0158 for it to have become such a successful zombie?

Click here to read complete article

Vulnerabilities Tags:Analysis, CVE, Microsoft, Word, zombie

Post navigation

Previous Post: Ignore Android security FUD, but buy a new phone anyway
Next Post: Security industry responds to NCA report

Related Articles

New Google Report Warns Of ‘Real And Significant Threat’ To User Privacy Google
Google Security Warning: First Hack Attack Of 2024—Update Chrome Now Google
Hackers Prompt Emergency Google 0-Day Attack Patch For Chrome Users Google
Photo of front end collision, crash test of cars This Surprisingly Simple Hack Can Crash iPhones—Update To iOS 17.2 Now Hacking
Google Chrome 120—Update Now As New Security Risks Revealed Google
New Critical Google Chrome Security Warning As 0-Day Exploit Confirmed Announcements

Categories

Post Archive

Tags

0day Analysis Android Apple Apps breach bug bounty Business Chrome crime Cybercrime Data Protection Encryption Enterprise Google Government Hackers Hacking Health healthcare industry iOS IoT iPhone Malware Microsoft News NHS Opinion passwords Phishing Privacy ransomware Research Russia Samsung threat intelligence Twitter Update Vulnerabilites vulnerabilities Vulnerability Windows Windows 10 zero-day

Copyright © 2025 Davey Winder .

×
Cookies
We serve cookies. If you think that's ok, just click "Accept all". You can also choose what kind of cookies you want by clicking "Settings". Read our cookie policy
Settings Refuse all Accept all
Cookies
Choose what kind of cookies to accept. Your choice will be saved for one year. Read our cookie policy
  • Necessary
    These cookies are not optional. They are needed for the website to function.
  • Statistics
    In order for us to improve the website's functionality and structure, based on how the website is used.
  • Experience
    In order for our website to perform as well as possible during your visit. If you refuse these cookies, some functionality will disappear from the website.
  • Marketing
    By sharing your interests and behavior as you visit our site, you increase the chance of seeing personalized content and offers.
Save Refuse all Accept all
GDPR Cookie Policy