Microsoft
Visual Basic for Applications (VBA)
Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability - Active in CISA KEV catalog.
2026-04-14
Description
Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability - Active in CISA KEV catalog.
Remediation
FEDERAL DEADLINE: April 26, 2026 (13 days). Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. FEDERAL DEADLINE: April 26, 2026 (13 days). Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA KEV Details
Deadline: April 26, 2026
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Appeared in Briefs
April 26, 2026
April 25, 2026
April 24, 2026
April 23, 2026
April 22, 2026
April 21, 2026
April 20, 2026
April 19, 2026
April 18, 2026
April 17, 2026
April 16, 2026
April 15, 2026
April 14, 2026
---METADATA---
VENDOR: D-Link
PRODUCT: Routers (DIR-300)
AFFECTED_VERSIONS: See vendor advisory for specific affected versions
---END_METADATA---
Description Summary:
An OS command injection vulnerability exists in multiple D-Link router models, potentially allowing unauthorized remote code execution.
Executive Summary:
A critical OS command injection vulnerability in D-Link routers poses a severe risk of unauthorized remote code execution and full system compromise.
Vulnerability Details
CVE-ID: CVE-2013-10050
Affected Software: D-Link Routers
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: This vulnerability involves an OS command injection flaw within the device firmware, which may be triggered by an attacker to execute arbitrary system commands. The authentication requirements remain unconfirmed; however, such flaws typically do not require elevated privileges if reachable via the WAN interface.
Business Impact
The ability to inject OS commands allows an attacker to gain full control over the network gateway. This risk carries a CVSS score of 8.8, indicating a high severity that could lead to complete network interception, traffic redirection, and exfiltration of sensitive internal data, resulting in significant operational downtime.
Remediation Plan
Immediate Action: Identify and inventory all affected D-Link hardware and apply the latest firmware updates provided by the vendor immediately.
Proactive Monitoring: Monitor network traffic for unusual outbound connections or shell-like commands originating from the router's management interface.
Compensating Controls: Restrict management interface access to trusted internal IP addresses only and disable remote administration features (WAN-side) where possible.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of May 27, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
Given the high CVSS score, this vulnerability represents a significant threat to network integrity. IT administrators must prioritize patching these devices or replacing them if they are end-of-life, as they serve as the primary perimeter defense for the local network.