Apply updates per vendor instructions.
Evidence dossier
CVE-2012-2539
CVE-2012-2539
gen-409cbd0cNormalized restatement
Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "Word RTF 'listoverridecount' Remote Code Execution Vulnerability."
- State
- PUBLISHED
- Published
- Dec 12, 2012
- Updated
- Oct 22, 2025
- Evidence coverage
- 72%
2026-07-18 · v2026.06.15 · percentile 98.9%
Distinct CVSS assessments remain side by side; none are averaged.
Source comparison
Who said what
Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "Word RTF 'listoverridecount' Remote Code Execution Vulnerability."
Microsoft Word Remote Code Execution Vulnerability
Probability 0.531590000000; percentile 0.988610000000
Applicability
Cited product scope
Grouped from 1 configuration nodes in this exact generation. Visual grouping does not establish asset exposure or common root cause.
Identity source boundaries
- cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
6 scope groups
[{"status": "affected", "version": "n/a"}]Version not applicableCanonical identity product-fe758137686484ffb07abeab90c90f69f48242b9bb56d3d0eb99f12d1ca3aa5dlinked exactInspect 2 returned assertions
cpe:2.3:a:microsoft:office_compatibility_pack:-:sp3:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
71af058a-2e5d-4b11-88db-8903c64b13c1
cpe:2.3:a:microsoft:office_compatibility_pack:-:sp2:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
55aa5cc4-af80-49a2-acd1-5644aa971044
Version 2010Canonical identity product-6b07be839c22a72d6880acf7867b5adcdaa8bac4efd0fecd0302a4174f76d2b6linked exactInspect 1 returned assertions
cpe:2.3:a:microsoft:office_web_apps:2010:sp1:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
343eeb54-c1b1-4d7b-8780-5b5a5f2f840c
Version not applicableCanonical identity product-d4961dfd8a4399733262c3c8374d834756c5c17f84bd52de66db3993629d4b40linked exactInspect 1 returned assertions
cpe:2.3:a:microsoft:office_word_viewer:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c64b2636-8f96-48ba-921f-a8fa0e62de63
Version 2010Canonical identity product-77f9def9702aa8ece74aa62c4de32bc72b167cb6f10f2eff44492cf46afc2e03linked exactInspect 1 returned assertions
cpe:2.3:a:microsoft:sharepoint_server:2010:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
dcbcb0a0-bc40-4e6b-bd06-a137bb964b7f
Version 2003; Version 2007; Version 2010Canonical identity product-c8093d22ed2cea792c0cc0ce039b1c82530e9d7a56e9ab1184596470080024c2linked exactInspect 4 returned assertions
cpe:2.3:a:microsoft:word:2007:sp3:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7d006508-bfb0-4f21-a361-3da644f51d8a
cpe:2.3:a:microsoft:word:2007:sp2:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
262bc12c-246a-41ab-a08d-3d205156f074
cpe:2.3:a:microsoft:word:2003:sp3:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
80f8e09e-e7f7-4d86-b140-3933edc54e1c
cpe:2.3:a:microsoft:word:2010:sp1:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d2a0758c-6499-407f-823a-6f28be56805e
Assessments
CVSS by origin
AV:N/AC:M/Au:N/C:C/I:C/A:CCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HLimitations and unknowns
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
- NVD-carried upstream facts remain derivative and are not independent corroboration.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Factor D remains unknown because WC-03 has not converted canonical CPE mappings into generation-bound mapping obligations; canonical identity alone does not score applicability.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.