CVE Vulnerabilities

CVE-2012-1854

Published: Jul 10, 2012 | Modified: Oct 12, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka Visual Basic for Applications Insecure Library Loading Vulnerability, as exploited in the wild in July 2012.

Affected Software

Name Vendor Start Version End Version
Office Microsoft 2003-sp3 (including) 2003-sp3 (including)
Office Microsoft 2007-sp2 (including) 2007-sp2 (including)
Office Microsoft 2007-sp3 (including) 2007-sp3 (including)
Office Microsoft 2010 (including) 2010 (including)
Office Microsoft 2010-sp1 (including) 2010-sp1 (including)
Visual_basic_for_applications Microsoft * *
Visual_basic_for_applications_sdk Microsoft * *

References