CVE Vulnerabilities

CVE-2012-1854

Published: Jul 10, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka Visual Basic for Applications Insecure Library Loading Vulnerability, as exploited in the wild in July 2012.

Affected Software

NameVendorStart VersionEnd Version
OfficeMicrosoft2003-sp3 (including)2003-sp3 (including)
OfficeMicrosoft2007-sp2 (including)2007-sp2 (including)
OfficeMicrosoft2007-sp3 (including)2007-sp3 (including)
OfficeMicrosoft2010 (including)2010 (including)
OfficeMicrosoft2010-sp1 (including)2010-sp1 (including)
Visual_basic_for_applicationsMicrosoft**
Visual_basic_for_applications_sdkMicrosoft**

References