CVE-2012-0013
MS12-005 Microsoft Office ClickOnce Unsafe Object Package Handling Vulnerability
Title source: metasploitDescription
Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted ClickOnce application in a Microsoft Office document, related to .application files, aka "Assembly Execution Vulnerability."
Exploits (3)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/19037
exploitdb
WORKING POC
by Byoungyoung Lee · textlocalwindows
https://www.exploit-db.com/exploits/18372
metasploit
WORKING POC
EXCELLENT
by Yorick Koster, sinn3r · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/ms12_005.rb
References (6)
Scores
EPSS
0.8646
EPSS Percentile
99.4%
Details
Status
published
Products (6)
microsoft/windows_7
(3 CPE variants)
microsoft/windows_server_2003
microsoft/windows_server_2008
(3 CPE variants)
microsoft/windows_server_2008
r2 (2 CPE variants)
microsoft/windows_vista
microsoft/windows_xp
(2 CPE variants)
Published
Jan 10, 2012
Tracked Since
Feb 18, 2026