Visual Basic for Applications Remote Code Execution Vulnerability (2707960)

Summary
This host is missing a critical security update according to Microsoft Bulletin MS12-046.
Impact
Successful exploitation will allow remote attackers to execute arbitrary code affected system. Impact Level: System/Application
Solution
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link, http://technet.microsoft.com/en-us/security/bulletin/ms12-046
Insight
Microsoft Visual Basic for Applications incorrectly restricts the path used for loading external libraries, which can be exploited by tricking a user to open a legitimate Microsoft Office related file located in the same network directory as a specially crafted dynamic link library (DLL) file.
Affected
Microsoft Visual Basic for Applications Microsoft Office 2003 Service Pack 3 and prior Microsoft Office 2007 Service Pack 3 and prior Microsoft Office 2010 Service Pack 1 and prior
References