Summary
This host is missing a critical security update according to Microsoft Bulletin MS12-046.
Impact
Successful exploitation will allow remote attackers to execute arbitrary code affected system.
Impact Level: System/Application
Solution
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link, http://technet.microsoft.com/en-us/security/bulletin/ms12-046
Insight
Microsoft Visual Basic for Applications incorrectly restricts the path used for loading external libraries, which can be exploited by tricking a user to open a legitimate Microsoft Office related file located in the same network directory as a specially crafted dynamic link library (DLL) file.
Affected
Microsoft Visual Basic for Applications
Microsoft Office 2003 Service Pack 3 and prior
Microsoft Office 2007 Service Pack 3 and prior
Microsoft Office 2010 Service Pack 1 and prior
References
- http://osvdb.org/show/osvdb/83655
- http://secunia.com/advisories/49800/
- http://support.microsoft.com/KB/2598361
- http://support.microsoft.com/kb/976321
- http://support.microsoft.com/kb/2553447
- http://support.microsoft.com/kb/2598243
- http://support.microsoft.com/kb/2688865
- http://support.microsoft.com/kb/KB2598361
- http://technet.microsoft.com/en-us/security/bulletin/ms12-046
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2012-1854 -
CVSS Base Score: 6.9
AV:L/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Microsoft Window Audio Service Privilege Escalation Vulnerability (3005607)
- Microsoft Windows DirectWrite Denial of Service Vulnerability (2665364)
- Microsoft Windows Media Center Remote Code Execution Vulnerability (2978742)
- Microsoft Exchange and Windows SMTP Service Denial of Service Vulnerability (981832)
- Exchange 2000 Exhaust CPU Resources (Q320436)