Evidence dossier

CVE-2012-2539

CVE-2012-2539

74.192.8Priority evidence range
As known Jul 21, 2026, 8:13 AM UTCgen-409cbd0c

Normalized restatement

Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "Word RTF 'listoverridecount' Remote Code Execution Vulnerability."

State
PUBLISHED
Published
Dec 12, 2012
Updated
Oct 22, 2025
Evidence coverage
72%
CISA KEVCatalog member

Apply updates per vendor instructions.

FIRST EPSS53.16%

2026-07-18 · v2026.06.15 · percentile 98.9%

Source stateConflict visible

Distinct CVSS assessments remain side by side; none are averaged.

Source comparison

Who said what

CISA-ADPindependent enrichment
container

CISA ADP Vulnrichment

CVEderivative copy
container

CVE Program Container

microsoftoriginal assertion
container

Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "Word RTF 'listoverridecount' Remote Code Execution Vulnerability."

CISA KEVoriginal assertion
observed_exploitation

Microsoft Word Remote Code Execution Vulnerability

FIRST EPSSoriginal assertion
model_probability

Probability 0.531590000000; percentile 0.988610000000

Applicability

Cited product scope

Trace impact →
9Underlying assertions
5Canonical products
9Target assertions
0Constraint assertions

Grouped from 1 configuration nodes in this exact generation. Visual grouping does not establish asset exposure or common root cause.

Identity source boundaries
  • cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

6 scope groups

microsoft · source assertedn/an/aDirect source scope
[{"status": "affected", "version": "n/a"}]
unknown
NVD CPE · APPLICATIONmicrosoftoffice_compatibility_packVulnerable target · 2 assertions
Version not applicableCanonical identity product-fe758137686484ffb07abeab90c90f69f48242b9bb56d3d0eb99f12d1ca3aa5dlinked exact
supported
Inspect 2 returned assertions
  1. cpe:2.3:a:microsoft:office_compatibility_pack:-:sp3:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    71af058a-2e5d-4b11-88db-8903c64b13c1
  2. cpe:2.3:a:microsoft:office_compatibility_pack:-:sp2:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    55aa5cc4-af80-49a2-acd1-5644aa971044
NVD CPE · APPLICATIONmicrosoftoffice_web_appsVulnerable target · 1 assertions
Version 2010Canonical identity product-6b07be839c22a72d6880acf7867b5adcdaa8bac4efd0fecd0302a4174f76d2b6linked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:a:microsoft:office_web_apps:2010:sp1:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    343eeb54-c1b1-4d7b-8780-5b5a5f2f840c
NVD CPE · APPLICATIONmicrosoftoffice_word_viewerVulnerable target · 1 assertions
Version not applicableCanonical identity product-d4961dfd8a4399733262c3c8374d834756c5c17f84bd52de66db3993629d4b40linked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:a:microsoft:office_word_viewer:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c64b2636-8f96-48ba-921f-a8fa0e62de63
NVD CPE · APPLICATIONmicrosoftsharepoint_serverVulnerable target · 1 assertions
Version 2010Canonical identity product-77f9def9702aa8ece74aa62c4de32bc72b167cb6f10f2eff44492cf46afc2e03linked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:a:microsoft:sharepoint_server:2010:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    dcbcb0a0-bc40-4e6b-bd06-a137bb964b7f
NVD CPE · APPLICATIONmicrosoftwordVulnerable target · 4 assertions
Version 2003; Version 2007; Version 2010Canonical identity product-c8093d22ed2cea792c0cc0ce039b1c82530e9d7a56e9ab1184596470080024c2linked exact
supported
Inspect 4 returned assertions
  1. cpe:2.3:a:microsoft:word:2007:sp3:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7d006508-bfb0-4f21-a361-3da644f51d8a
  2. cpe:2.3:a:microsoft:word:2007:sp2:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    262bc12c-246a-41ab-a08d-3d205156f074
  3. cpe:2.3:a:microsoft:word:2003:sp3:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    80f8e09e-e7f7-4d86-b140-3933edc54e1c
  4. cpe:2.3:a:microsoft:word:2010:sp1:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d2a0758c-6499-407f-823a-6f28be56805e

Assessments

CVSS by origin

9.3
nvd@nist.govCVSS 2.0 · role PrimaryAV:N/AC:M/Au:N/C:C/I:C/A:C
7.8
134c704f-9b21-4f2e-91b3-4a467353bcc0CVSS 3.1 · role SecondaryCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8
CISA-ADPCVSS 3.1 · role unknownCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Limitations and unknowns

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
  • NVD-carried upstream facts remain derivative and are not independent corroboration.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Factor D remains unknown because WC-03 has not converted canonical CPE mappings into generation-bound mapping obligations; canonical identity alone does not score applicability.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.