Vulnerability Description
ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, which allows user-assisted remote attackers to execute arbitrary VBA code via a crafted map (.mxd) file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Esri | Arcmap | <= 10.0.2.3200 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.org/files/113644/ESRI-ArcMap-Arbitrary-Code-ExecutionExploit
- http://www.cs.umb.edu/~joecohen/exploits/CVE-2012-1661/Exploit
- http://www.exploit-db.com/exploits/19138ExploitThird Party AdvisoryVDB Entry
- http://www.osvdb.org/82986Broken Link
- http://www.securitytracker.com/id?1027170ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.org/files/113644/ESRI-ArcMap-Arbitrary-Code-ExecutionExploit
- http://www.cs.umb.edu/~joecohen/exploits/CVE-2012-1661/Exploit
- http://www.exploit-db.com/exploits/19138ExploitThird Party AdvisoryVDB Entry
- http://www.osvdb.org/82986Broken Link
- http://www.securitytracker.com/id?1027170ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2012-1661?
CVE-2012-1661 is a vulnerability with a CVSS score of 9.3 (HIGH). ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, which allows user-assisted remote attackers to execute arbitrary VBA code via a cr...
How severe is CVE-2012-1661?
CVE-2012-1661 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-1661?
Check the references section above for vendor advisories and patch information. Affected products include: Esri Arcmap.