CVE-2012-1854

Description

Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka Visual Basic for Applications Insecure Library Loading Vulnerability, as exploited in the wild in July 2012.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.358

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Microsoft Office 2003 (KB2598361)Windows
Security Update for Microsoft Office 2007 suites (KB2596744)Windows
Security Update for Microsoft Office 2010 (KB2598243) 32-Bit EditionWindows
Security Update for Microsoft Office 2010 (KB2553447) 32-Bit EditionWindows
Security Update for Microsoft Office 2010 (KB2598243) 64-Bit EditionWindows
Security Update for Microsoft Office 2010 (KB2553447) 64-Bit EditionWindows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-12180Security Update for Microsoft Office 2007 suites (KB2596744)
PATCH-12181Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition
PATCH-12182Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition
PATCH-12183Security Update for Microsoft Office 2010 (KB2598243) 64-Bit Edition
PATCH-12184Security Update for Microsoft Office 2010 (KB2553447) 64-Bit Edition

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234