9.3
CVSSv2

CVE-2012-1661

Published: 12/07/2012 Updated: 16/07/2012
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and previous versions does not properly prompt users before executing embedded VBA macros, which allows user-assisted remote malicious users to execute arbitrary VBA code via a crafted map (.mxd) file.

Vulnerable Product Search on Vulmon Subscribe to Product

esri arcgis

esri arcgis 9.0

esri arcmap 9.0

Exploits

===== TITLE ===== ESRI ArcMap Arbitrary Code Execution Via Crafted Map File ============ Description: ============ Opening a specially crafted mxd file will execute arbitrary code without prompting and without a crash of the application This is due to a flaw in the programs ability to prompt a user before executing embedded VBA Mxd files are n ...
ESRI ArcMap suffers from an arbitrary code execution vulnerability when handling a specially crafted map file ...