๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2012-1854: Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability
Summary
Microsoft Visual Basic for Applications (VBA, a programming language used in Microsoft Office) has a vulnerability in how it loads libraries (pre-written code) that could let attackers run malicious code on your computer remotely. This flaw is currently being exploited by attackers in the real world.
Solution / Mitigation
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Vulnerability Details
EPSS: 1.4%
Yes
๐ฅ Actively Exploited
April 12, 2026
Classification
Taxonomy References
Original source: https://nvd.nist.gov/vuln/detail/CVE-2012-1854
First tracked: April 13, 2026 at 02:00 PM
Classified by LLM (prompt v3) ยท confidence: 95%