CVE-2012-1854Active Exploitation(microsoft / office)

MEDIUMCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (5 mentions)

Immediate actions

  • Patch microsoft office systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka "Visual Basic for Applications Insecure Library Loading Vulnerability," as exploited in the wild in July 2012.

5.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-04-27. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-426

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • office
  • visual_basic_for_applications
  • visual_basic_for_applications_sdk

Threat summary

  • Active exploitation appears in 10 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 15 mentions across 5 observed days

What's happening

  • Active exploitation reported across 10 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 11 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 5 mentions (2026-04-14); latest day: 5
  • 15 total mentions across 5 days

Affected systems

Vendors
Products
officevisual_basic_for_applicationsvisual_basic_for_applications_sdk

3 versions affected across 3 products

Deep dive

Activity timeline15 mentions / 5d
01345Mentions · 2026-04-13: 3Mentions · 2026-04-14: 5Mentions · 2026-04-15: 1Mentions · 2026-04-16: 1Mentions · 2026-05-01: 5PoC Mentioned / Linked · 2026-04-14: 1Active Exploitation · 2026-04-13: 3Active Exploitation · 2026-04-14: 3Active Exploitation · 2026-04-15: 1Active Exploitation · 2026-04-16: 1Active Exploitation · 2026-05-01: 2Patch / Workaround · 2026-04-14: 2Patch / Workaround · 2026-05-01: 1Technical Details · 2026-04-13: 2Technical Details · 2026-04-14: 4Technical Details · 2026-04-15: 1Technical Details · 2026-04-16: 1Technical Details · 2026-05-01: 304-1304-1404-1504-1605-01
Signal classification4 categories
Active Exploitation
1066.7%
Disclosure
213.3%
Patch
213.3%
General
16.7%
Referenced assets21 URLs
Classification over time
DateTotalLabels
2026-04-133
Active Exploitation3
2026-04-145
Active Exploitation3Disclosure1Patch1
2026-04-151
Active Exploitation1
2026-04-161
Active Exploitation1
2026-05-015
Active Exploitation2Disclosure1General1Patch1
Full discourse15 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Active Exploitation

    6 ثغرات تهدد اغلب الاجهزة والشبكات يتم استغلالها حاليا 🚨 CISA أضافت 6 ثغرات جديدة لقائمة (KEV)Known Exploited Vulnerabilities بعد تأكد الاستغلال الفعلي لها حاليا من قبل المخترقين. الثغرة CVE-2026-21643 (CVSS: 9.1) 🔴 المنتج: FortiClient EMS من Fortinet النوع: SQL Injection التأثير: تنفيذ كود خبيث بدون مصادقة الحالة: استغلال مؤكد منذ 24 مارس 2026 الثغرة CVE-2020-9715 (CVSS: 7.8)🟠 المنتج: Adobe Acrobat Reader النوع: Use-After-Free التأثير: Remote Code Execution ثغرة تستغل من (2020) ولكن تم اكتشافها والاعلان عنها مؤخرا الثغرة CVE-2023-36424 (CVSS: 7.8) 🟠 المنتج: Microsoft Windows Common Log File System Driver النوع: Out-of-Bounds Read التأثير: Privilege Escalation ما فيه تقارير استغلال علنية، بس CISA تؤكد انها تتسغل حاليا . الثغرة CVE-2023-21529 (CVSS: 8.8) 🔴 المنتج: Microsoft Exchange Server النوع: Deserialization of Untrusted Data التأثير: Remote Code Execution المجموعة الصينية Storm-1175 تستغلها لـ Medusa Ransomware. الثغرة CVE-2025-60710 (CVSS: 7.8)🟠 المنتج: Host Process for Windows Tasks النوع: Improper Link Resolution Before File Access التأثير: Local Privilege Escalation الثغرة CVE-2012-1854 (CVSS: 7.8) 📅🟠 المنتج: Microsoft Visual Basic for Applications (VBA) النوع: Insecure Library Loading التأثير: Remote Code Execution ثغرة من 2012! Microsoft عمرها ١٤ سنه ولاتزال تستغل

    Post summary

    This post enumerates six CVEs that CISA has confirmed as actively exploited, providing detailed technical data for each. No patches or PoC links are mentioned.

    16020152.6K
    49.2K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(4/13追加) 🛡️No.1561 CVE-2012-1854 Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability ✅概要 ・深刻度:重要 7.8 (CVSS Base) / CISA-ADP ・種別:信頼できない検索パス (CWE-426) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Microsoft Visual Basic for Applications (VBA) において、DLL検索パスの処理に不備が存在。事前認証されていない攻撃者により、細工されたDLLを特定ディレクトリに配置されることで、正規ライブラリにかわって読み込まされる恐れがある。結果、ユーザーが対象ファイルを開くことで、任意コードが実行される可能性がある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・攻撃者がDLLを配置できる環境であること ・ユーザーが細工されたファイルを開くこと ・VBAが有効な環境 ________________________________________ ✅悪用時影響 ・任意コード実行(ユーザー権限) ・情報漏えいおよび改ざん ・システム可用性への影響 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2012-1854 https://learn.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-046   🛡️No.1562 CVE-2025-60710 Microsoft Windows Link Following Vulnerability ✅概要 ・深刻度:重要 7.8 (CVSS Base) / Microsoft Corporation ・種別:リンク解釈の問題 (CWE-59) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Microsoft Windows において、リンク解決処理に不備が存在。認証済みの攻撃者により、細工されたリンクを介して、本来アクセスできないリソースへアクセスされ、ローカル環境で権限昇格される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・ローカルアクセスが可能であること ・低権限ユーザーであること ・ユーザー操作不要 ________________________________________ ✅悪用時影響 ・権限昇格 ・機密情報の取得および改ざん ・システムへの影響 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-60710 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-60710   🛡️No.1563 CVE-2023-21529 Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability ✅概要 ・深刻度:8.8 High (CVSS Base) / NVD ・種別:信頼できないデータのデシリアライゼーション (CWE-502) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Microsoft Exchange Serverにおいて、信頼できないデータのデシリアライズ処理に起因する脆弱性が存在。認証済みの攻撃者により、細工されたデータをサーバー上で処理されることで、コード実行される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・認証済みユーザ権限が必要 ・Exchange Serverへのネットワークアクセス ________________________________________ ✅悪用時影響 ・任意コード実行 ・情報漏えい、改ざん、サービス影響 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2023-21529 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21529   🛡️No.1564 CVE-2023-36424 Microsoft Windows Out-of-Bounds Read Vulnerability ✅概要 ・深刻度:7.8 High (CVSS Base) / NVD ・種別:境界外読み取り (CWE-125) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Microsoft Windowsにおいて、境界外読み取りに起因する脆弱性が存在。認証済みの攻撃者により、不正なメモリアクセスを引き起こされることで、機密情報を取得される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:高 ________________________________________ ✅攻撃前提条件 ・ローカルでのログオン権限が必要 ________________________________________ ✅悪用時影響 ・機密情報の漏えい ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2023-36424 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36424   🛡️No.1565 CVE-2020-9715 Adobe Acrobat Use-After-Free Vulnerability ✅概要 ・深刻度:7.8 High (CVSS Base) / NVD ・種別:解放後使用 (CWE-416) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Adobe AcrobatおよびReaderにおいて、解放後使用に起因する脆弱性が存在。事前認証されていない攻撃者により、細工されたPDFファイルをユーザーに開かせることで、メモリ破損を引き起こし、任意のコードを実行される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・ユーザが細工されたPDFファイルを開く必要がある ________________________________________ ✅悪用時影響 ・任意コード実行 ・情報の取得、改ざん、システム影響 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開済み ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2020-9715 https://helpx.adobe.com/security/products/acrobat/apsb20-48.html   🛡️No.1566 CVE-2026-21643 Fortinet FortiClientEMS SQL Injection Vulnerability ✅概要 ・深刻度:9.8 Critical (CVSS Base) / NVD ・種別:SQLインジェクション (CWE-89) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Fortinet FortiClientEMSにおいて、SQLコマンドで使用される特殊要素の不適切な無効化に起因する脆弱性が存在。事前認証されていない攻撃者により、細工されたHTTPリクエストを送信されることで、SQLインジェクションを引き起こされる恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・対象システムへネットワークアクセス可能 ________________________________________ ✅悪用時影響 ・任意コマンド実行 ・機密情報の漏えい、改ざん、サービス停止 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:あり(セキュリティ企業による報告) ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-21643 https://www.fortiguard.com/psirt/FG-IR-26-XXX   🛡️No.1567 CVE-2026-34621 Adobe Acrobat and Reader Prototype Pollution Vulnerability ✅概要 ・深刻度:8.6 High (CVSS Base) / Adobe Systems Incorporated ・種別:オブジェクトプロトタイプ属性の不適切に制御された変更 (プロトタイプの汚染) (CWE-1321) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Adobe AcrobatおよびReaderにおいて、オブジェクトプロトタイプ属性の不適切に制御された変更に起因する脆弱性が存在。ユーザー権限で任意のコードを実行される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・被害者が悪意のあるファイルを開く必要がある ・対象端末でAdobe AcrobatまたはReaderが利用されている必要がある ________________________________________ ✅悪用時影響 ・現在のユーザー権限で任意コード実行 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:Adobeが悪用を確認 (Adobeヘルプセンター) ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-34621 https://helpx.adobe.com/security/products/acrobat/apsb26-43.html https://www.cisa.gov/news-events/alerts/2026/04/13/cisa-adds-seven-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    The post confirms that CISA has detected exploitation of seven CVEs, lists detailed technical information, and provides vendor advisory links for patching, but does not provide active exploit code.

    000635.7K
    43.5K followersView on X
  • Elusive@ElusivePrivacy
    Active Exploitation

    CISA added 7 CVEs to the KEV catalog today. All confirmed active exploitation. CVE-2012-1854 — Microsoft VBA insecure library loading CVE-2020-9715 — Adobe Acrobat UAF CVE-2023-21529 — Exchange deserialization CVE-2023-36424 — Windows OOB read CVE-2025-60710 — Windows link following CVE-2026-21643 — Fortinet SQL injection CVE-2026-34621 — Adobe Acrobat prototype pollution A CVE from 2012 is still being actively exploited in 2026. Patch prioritization isn’t optional. Source: https://t.me/VulnerabilityNews/41878 → http://cisa.gov/known-exploited-vulnerabilities-catalog

    Post summary

    CISA identified seven CVEs with confirmed active exploitation, highlighting urgent patching necessity despite lacking detailed remediation steps.

    11030214
    184 followersView on X
  • CiberPlaneta@CiberPlanetaOrg
    Disclosure

    🛡️ CVE-2012-1854: Vulnerabilidad Crítica de Carga Insegura en Microsoft VBA Analizamos la CVE-2012-1854, una vulnerabilidad de carga insegura de bibliotecas en Visual Basic for Applications de Microsoft que permite ejecución remota de c https://www.ciberplaneta.org/vulnerabilidades/cve-2012-1854-vulnerabilidad-critica-de-carga-insegura-en-microsoft-vba/ #ciberplaneta #vulnerabilidades #cve_2012_1854 #cve #vulnerabilidad #microsoft #seguridad #infosec #ciberseguridad

    Post summary

    The post provides an overview of CVE‑2012‑1854, detailing its insecure library load mechanism in Microsoft VBA that permits remote execution, but does not include PoC, exploit code, patch information, or evidence of active exploitation.

    0101137
    6 followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISAが既知の悪用された脆弱性7件をカタログに追加 CISA Adds Seven Known Exploited Vulnerabilities to Catalog #CISA (Apr 13) CVE-2012-1854 Microsoft Visual Basic for Applications のライブラリ読み込みの脆弱性 CVE-2020-9715 Adobe AcrobatのUse-After-Free脆弱性 CVE-2023-21529 Microsoft Exchange Serverにおける信頼できないデータの逆シリアル化の脆弱性 CVE-2023-36424 Microsoft Windows 境界外読み取りの脆弱性 CVE-2025-60710 Microsoft Windows リンク追跡の脆弱性 CVE-2026-21643 FortinetのSQLインジェクション脆弱性 CVE-2026-34621 Adobe AcrobatおよびReaderプロトタイプ汚染の脆弱性 https://www.cisa.gov/news-events/alerts/2026/04/13/cisa-adds-seven-known-exploited-vulnerabilities-catalog

    Post summary

    CISA’s alert lists seven CVEs that are confirmed to be exploited in the wild, providing brief technical details for each but no patches or PoC information.

    00030341
    4.9K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2012-1854-visual-basic-for-applications-vba #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The linked research page indicates that CVE-2012-1854, affecting Visual Basic for Applications, is being actively exploited in the wild.

    0001026
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Vendor fixes were released under Microsoft’s 2012 security guidance for this issue (referenced by NVD as MS12-046), and applying the vendor’s update or mitigations remains the authoritative remediation path NVD CVE-2012-1854. CISA’s KEV directive requires organizations to…

    Post summary

    Microsoft released vendor fixes for CVE‑2012‑1854, and applying the update or mitigations is the recommended remediation.

    1000027
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    NVD classifies CVE-2012-1854 as enabling arbitrary code execution when a vulnerable component loads a library from a directory controlled by an attacker NVD CVE-2012-1854. The affected product is Microsoft Visual Basic for Applications (VBA), the runtime embedded in…

    Post summary

    The text provides a basic NVD classification for CVE-2012-1854, highlighting it as a remote code execution flaw involving an attacker‑controlled directory, but offers no PoC, exploit, patch, or evidence of active attacks.

    1000024
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2012-1854: CISA added CVE-2012-1854 (VBA insecure library loading) to KEV; remote code execution via untrusted search path (CWE-426). What happened CISA added CVE-2012-1854 — an insecure library loading issue in Microsoft Visual Basic for Applications (VBA) — to the…

    Post summary

    CISA added CVE‑2012‑1854 to its KEV list, signaling that this VBA library‑loading flaw is actively exploited, though no PoC, exploit code, patch, or false‑positive claim is discussed.

    1000031
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    This is a classic DLL search order hijack (CWE-426) scenario, which historically yields reliable execution without needing macro enablement or exploit chains, provided the victim resolves the library from an attacker-chosen path NVD CVE-2012-1854. Long-tail vulnerabilities…

    Post summary

    The text describes a classic DLL search order hijack vulnerability (CWE-426) for CVE-2012-1854, but offers no further exploit or remediation details.

    1000022
    152 followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Active Exploitation

    CISAが既知の悪用された脆弱性7件をカタログに追加 https://www.cisa.gov/news-events/alerts/2026/04/13/cisa-adds-seven-known-exploited-vulnerabilities-catalog CVE-2012-1854 Microsoft Visual Basic for Applications のライブラリ読み込みの脆弱性 CVE-2020-9715 Adob​​e AcrobatのUse-After-Free脆弱性

    Post summary

    CISA has added seven known exploited vulnerabilities, including CVE-2012-1854 (VB for Applications library loading flaw) and CVE-2020-9715 (Adobe Acrobat Use-After-Free), to its catalog, confirming active exploitation in the wild.

    1000056
    40 followersView on X
  • CiberPlaneta@CiberPlanetaOrg
    Patch

    🛡️ Alerta de Seguridad: Vulnerabilidad en Carga Insegura de Bibliotecas en Microsoft Visual Basic for Applications (CVE-2012-1854) Vulnerabilidad CWE-426 en Microsoft VBA permite ejecución remota de código mediante carga insegura de bibliotecas. CVSS 7.8 (Alta). Afecta componentes de Office. Parche disponible en MS12-046. Fecha límite FCEB: 2026-04-27. https://www.ciberplaneta.org/boletines/91/ #ciberplaneta #bulletin #cybersecurity #cve #microsoft #visual_basic_for_applications_vba #ioc #infosec #ciberseguridad

    Post summary

    The bulletin warns of a high‑severity RCE flaw in Microsoft VBA (CVE‑2012‑1854) and announces that Microsoft’s MS12‑046 patch is available, with no indication of active exploitation.

    0000030
    6 followersView on X
  • Assaf Kipnis@KTLYST_labs
    Active Exploitation

    CVE-2012-1854. Twelve years old. Still on CISA KEV. The CVE isn't the problem. The advisory hit inboxes, a couple of IOCs got blocked, and the context never reached endpoint, IAM, or patch teams. The nervous system is missing.

    Post summary

    CVE-2012-1854 remains listed on the CISA KEV, implying it is still being exploited, yet no PoC, exploit code, patch, or technical details are provided.

    0000018
    30 followersView on X
  • ScyScan@ScyScan
    Active Exploitation

    Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2012-1854 #Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability https://www.scyscan.com/cve-2012-1854/microsoft-visual-basic-for-applications-insecure-library-loading-vulnerability/

    Post summary

    The post lists CVE-2012-1854 as a known exploited vulnerability for Microsoft Visual Basic for Applications, indicating active exploitation; it describes the issue as an insecure library loading flaw but offers no PoC, exploit code, patch, or debunking.

    0000031
    61 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    🚨 BREAKING: CISA updates its Known Exploited Vulnerabilities Catalog with seven new entries, including CVE-2012-1854 and CVE-2020-9715. These vulnerabilities are actively exploited, urging immediate attention from IT teams. #CyberSecurity #BreakingNews https://t.co/m8vrB0xob7

    Post summary

    The tweet announces that CISA has added seven CVEs, including CVE-2012-1854 and CVE-2020-9715, to its Known Exploited Vulnerabilities catalog, noting that these flaws are actively exploited and urging IT teams to act.

    0000028
    55 followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftoffice2003--
Appmicrosoftoffice2007--
Appmicrosoftoffice2007--
Appmicrosoftoffice2010-x64
Appmicrosoftoffice2010-x86
Appmicrosoftoffice2010-x64
Appmicrosoftoffice2010-x86
Appmicrosoftvisual_basic_for_applications---
Appmicrosoftvisual_basic_for_applications_sdk---

Explore more