보안뉴스 아카이브
긴급도 73/100 심각도 7.8 · 높음 악용확률 97.4% CISA KEV · 2026-04-13 CWE-426

CVE-2012-1854

CISA 기관 조치 기한: 2026-04-27

Microsoft Visual Basic for Applications (VBA)

Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka "Visual Basic for Applications Insecure Library Loading Vulnerability," as exploited in the wild in July 2012.
KEV 필수 조치: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

벡터: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

NVD 상세 ↗   참고 링크 ↗

← 취약점 목록