CVE-2012-0013

MS12-005 Microsoft Office ClickOnce Unsafe Object Package Handling Vulnerability

Title source: metasploit
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2012-0013. PoCs published by Metasploit, Byoungyoung Lee, Yorick Koster, sinn3r, including Metasploit module exploits/windows/fileformat/ms12_005.

AI-analyzed exploit summary This Metasploit module exploits CVE-2012-0013 by crafting a malicious Office Macro document that bypasses ClickOnce's unsafe object handling, allowing arbitrary code execution via a Python or Ruby payload that downloads and executes an executable.

Description

Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted ClickOnce application in a Microsoft Office document, related to .application files, aka "Assembly Execution Vulnerability."

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/19037

This Metasploit module exploits CVE-2012-0013 by crafting a malicious Office Macro document that bypasses ClickOnce's unsafe object handling, allowing arbitrary code execution via a Python or Ruby payload that downloads and executes an executable.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office Word 2007/2010 on Windows 7
No auth needed
Prerequisites: Victim must open the malicious document · Network connectivity to download the executable payload
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC
by Byoungyoung Lee · textlocalwindows
https://www.exploit-db.com/exploits/18372

This exploit leverages a vulnerability in Microsoft Windows (CVE-2012-0013) via a malicious macro-enabled document (18372.docm). When executed, it runs a Python script to achieve arbitrary code execution, demonstrating a remote code execution (RCE) attack vector.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Windows 7 32-bit (fully patched until Jan 2012)
No auth needed
Prerequisites: Macro execution enabled in Microsoft Office · Python interpreter installed on target system
devstral-2 · analyzed Feb 18, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Yorick Koster, sinn3r · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/ms12_005.rb

This Metasploit module exploits CVE-2012-0013 by crafting a malicious Office Macro document that bypasses ClickOnce security warnings to execute arbitrary code via embedded Python or Ruby payloads.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office Word 2007/2010 on Windows 7
No auth needed
Prerequisites: Victim must open the malicious document
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/51284
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA12-010A.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/47480
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14197
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1026497

Scores

EPSS 0.7375
EPSS Percentile 99.4%

Details

Status published
Products (6)
microsoft/windows_7 (3 CPE variants)
microsoft/windows_server_2003
microsoft/windows_server_2008 (3 CPE variants)
microsoft/windows_server_2008 r2 (2 CPE variants)
microsoft/windows_vista
microsoft/windows_xp (2 CPE variants)
Published Jan 10, 2012
Tracked Since Feb 18, 2026