← back
CVE-2012-1854

CVE-2012-1854

CVSS 7.8 HIGHEPSS 21.0%● KEVCWE-426
In short

Microsoft Office and Visual Basic for Applications load DLL files from the current folder without checking if they're trustworthy, allowing someone to place a malicious DLL in the same folder as a Word document to gain control when the document is opened.

Technical detail

DLL search path hijacking vulnerability in VBE6.dll (CWE-426) affecting Office 2003-2010 and VBA SDK; local attackers can plant malicious DLLs in the working directory where Office files reside, leading to arbitrary code execution with user privileges through insecure library loading without verification of DLL source.

Summary generated and translated by AI from the official description.
Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka "Visual Basic for Applications Insecure Library Loading Vulnerability," as exploited in the wild in July 2012.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
n/a · n/a

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →