Disclosure summary
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption.
CISA remediation guidance
Apply updates per vendor instructions.
Original records & references
PUBLISHED 2022-03-03T00:00:00-05:00
MODIFIED 2022-03-03T00:00:00-05:00
INGESTED 2026-10-06T11:42:59-04:00