CVE-2012-1661

Esri Arcmap < 10.0.2.3200 - Code Injection

Title source: rule
STIX 2.1

Description

ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, which allows user-assisted remote attackers to execute arbitrary VBA code via a crafted map (.mxd) file.

Exploits (1)

exploitdb WORKING POC
by Boston Cyber Defense · textlocalwindows
https://www.exploit-db.com/exploits/19138

References (5)

Core 5
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/19138
Exploit, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1027170
Broken Link vdb-entry x_refsource_osvdb
http://www.osvdb.org/82986

Scores

EPSS 0.0121
EPSS Percentile 79.1%

Details

CWE
CWE-94
Status published
Products (1)
esri/arcmap < 10.0.2.3200
Published Jul 12, 2012
Tracked Since Feb 18, 2026