CVE-2012-1661
CVE-2012-1661
ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, which allows user-assisted remote attackers to execute arbitrary VBA code via a crafted map (.mxd) file.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencepacketstormsecurity.org/files/113644/ESRI-ArcMap-Arbitrary-Code-Execution.htmlunverifiedcve_referencewww.exploit-db.com/exploits/19138unverifiedexploitdbwww.exploit-db.com/exploits/19138unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →