CVE-2012-2539: Microsoft Word Remote Code Execution Vulnerability

High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2022-03-28. EPSS: 53% chance of exploitation in the next 30 days.

Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "Word RTF 'listoverridecount' Remote Code Execution Vulnerability."

Affected products

  • Microsoft Office Compatibility Pack: affected versions not specified
  • Microsoft Office Web Apps: version 2010 only
  • Microsoft Office Word Viewer: affected versions not specified
  • Microsoft SharePoint Server: version 2010 only
  • Microsoft Word: version 2003 only; version 2007 only; version 2010 only

Published 2012-12-12. Last modified 2026-06-16.