CVE-2012-1854
high
📛 Threat Title
Microsoft Visual Basic for Applications (VBA): Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability
Description
Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution. Added to KEV: 2026-04-13. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Due date: 2026-04-27.
Indicators of Compromise (2)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
cve
CVE-2012-1854
IOC database
- Type
- cve
- Value
CVE-2012-1854- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cwe
CWE-426
IOC database
- Type
- cwe
- Value
CWE-426- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- CISA notes reference CISA KEV
-
NVD detail: CVE-2012-1854
CISA Known Exploited Vulnerabilities
Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution.
Remediations (9)
-
web:www.secure.com
Remediation fully removes a vulnerability by fixing its root cause — through a patch , code fix , or system replacement. Mitigation reduces the risk of exploitation without removing the flaw itself, using controls like network segmentation or access restrictions.
-
web:learn.microsoft.com
Since SFC found corrupted files but was unable to repair some of them, your best option is to perform an In-place Upgrade. This procedure reinstalls Windows, which helps fix file corruption and other issues. This procedure will also take your system to version 24H2. But don't worry. It's a simple procedure, and you have the option to keep files, settings, and apps. Therefore, all your data is ...
-
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
-
web:support.microsoft.com
Summary Improvements and fixes included in this update How to obtain and install the update How to obtain or download the latest cumulative update package for Linux More information File information Information about protection and security Summary This security update contains fixes and resolves vulnerabilities. To learn more about the vulnerabilities, see the following security advisories ...
-
web:support.servicenow.com
Overview The advisories below document publicly disclosed Common Vulnerabilities and Exposures ( CVEs ) in the Now Platform by ServiceNow. Because ServiceNow uses various methods to communicate vulnerability information, patches, and other fixes, customers should review family, security patch , and hotfix release notes, which are available at https://docs.servicenow.com, for a complete list of ...
-
web:attack.mitre.org
Software configuration refers to making security-focused adjustments to the settings of applications, middleware, databases, or other software to mitigate potential threats. These changes help reduce the attack surface, enforce best practices, and protect sensitive data. This mitigation can be implemented through the following measures: Conduct a Security Review of Application Settings: Review ...
-
web:www.cisa.gov
Patches are software and operating system (OS) updates that address security vulnerabilities within a program or product. Software vendors may choose to release updates to fix performance bugs, as well as to provide enhanced security features.
-
web:www.forbes.com
As security researchers warn about a dangerous Microsoft Windows update that isn't legitimate, users must pay close attention to what they are actually downloading.
-
CISA KEV
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Due date: 2026-04-27 Known ransomware campaign use: Unknown
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.