References https://learn.microsoft.com/zh-cn/security-updates/securitybulletins/2012/ms12-027 https://support.microsoft.com/zh-cn/topic/ms12-027-mscomctl-ocx-%E4%B8%AD%E7%9A%84%E6%BC%8F%E6%B4%9E%E5%8F%AF%E8%83%BD%E5%85%81%E8%AE%B8%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C-2012-%E5%B9%B4-4-%E6%9C%88-10-%E6%97%A5-e75d6f0c-90b8-ddc8-a656-9d0ff2f95604 https://learn.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-027 https://www.tenable.com/plugins/nessus/58659 https://www.anquanke.com/post/id/91643 https://support.microsoft.com/en-us/topic/ms12-027-description-of-the-security-update-for-2007-microsoft-office-system-april-10-2012-ef3aa0e1-7681-4314-53e2-38fa78ebd645 https://www.exploit-db.com/exploits/18780 https://thehackernews.com/2012/04/microsofts-april-security-update-patch.html https://www.microsoft.com/en-us/msrc/blog/2012/04/ms12-027-enhanced-protections-regarding-activex-controls-in-microsoft-office-documents https://support.microsoft.com/en-us/topic/ms12-027-vulnerability-in-mscomctl-ocx-could-allow-remote-code-execution-april-10-2012-e75d6f0c-90b8-ddc8-a656-9d0ff2f95604
Related VulnerabilitiesPoCjohnson-controls-default-login: Johnson Controls Frick Quantum HD Compressors - Default LoginPoCCVE-2026-58644: Microsoft SharePoint Server - WS-Federation BinaryFormatter Deserialization RCEMicrosoft SharePoint /_layouts/15/ToolPane.aspx 代码执行漏洞(CVE-2025-53770)Microsoft SharePoint Server /_trust/default.aspx 代码执行漏洞(CVE-2026-50522)Microsoft SharePoint Server JWT 权限绕过漏洞(CVE-2026-55040)PoC蓝凌EIS智慧协同平台 /common/FI_SelEmp.aspx SQL 注入漏洞方向标邮件网关 /common/cgi/get_audit.cgi 命令执行漏洞方向标邮件网关 /common/cgi/download.cgi 代码执行漏洞网神SecGate3600防火墙 /attachements/libcommon.log 信息泄露漏洞速达软件 /common/print/print!doSavePrintTpl.action Struts2 代码执行漏洞同鑫T9eHR信息化管理系统 /Common/GetDropDownList SQL 注入漏洞全程云OA /OA/Common/API/Huawei.asmx SQL 注入漏洞PoC全程云OA /oa/Common/WF/WorkFlow/WorkFlow.asmx SQL 注入漏洞