Skip to content
Appaloosa Scout
Language selector
fr en

KEV · Actively exploited

CVE-2012-1854

CVE-2012-1854 is actively exploited (CISA KEV catalog) : high severity (CVSS 7.8), 2 tracked apps concerned, none still exposed on their current version.

Severity (CVSS)
7.8

NVD scale

Exploitation
Confirmed
Tracked apps
2
Still exposed
0

Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka "Visual Basic for Applications Insecure Library Loading Vulnerability," as exploited in the wild in July 2012.

Attack vector : Local No privileges required
Show raw CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA Known Exploited Vulnerability

Added to KEV
2026-04-13
Remediation deadline
2026-04-27
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Ransomware
Unknown (not documented by CISA)

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

Vulnerable CPE configurations (14)
Vendor Product Versions
microsoft office
All platforms (wildcard)
-
microsoft office
All platforms (wildcard)
-
microsoft office
All platforms (wildcard)
-
microsoft office
All platforms (wildcard)
-
microsoft office
All platforms (wildcard)
-
microsoft office
All platforms (wildcard)
-
microsoft office
All platforms (wildcard)
-
microsoft office
All platforms (wildcard)
-
microsoft office
All platforms (wildcard)
-
microsoft office
All platforms (wildcard)
-
microsoft office
All platforms (wildcard)
-
microsoft office
All platforms (wildcard)
-
microsoft office
All platforms (wildcard)
-
microsoft office
All platforms (wildcard)
-
View on NVD ↗ CISA KEV catalog ↗ Advisory · docs.microsoft.com Advisory · learn.microsoft.com