CVE-2012-1854 - Microsoft Visual Basic for Applications (VBA)
AI Vulnerability ContextUntrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka "Visual Basic for Applications Insecur...
Overview
A source-backed snapshot of this vulnerability.
Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka "Visual Basic for Applications Insecure Library Loading Vulnerability," as exploited in the wild in July 2012.
Vulnerability status
How serious this vulnerability is and whether it is known to be exploited.
- CVE ID
- CVE-2012-1854
- Vendor/project
- Microsoft
- Product
- Visual Basic for Applications (VBA)
- Vulnerability name
- Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability
- Date added
- 2026-04-13
- Due date
- 2026-04-27
- Known ransomware campaign use
- Unknown
- CVSS v3
- 7.8
Exploit context
What the vulnerability is about.
Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka "Visual Basic for Applications Insecure Library Loading Vulnerability," as exploited in the wild in July 2012.
Source evidence
Original public records and references for this page.
Original source
Original source links
Open the public records and source datasets used for this page.
