ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, which allows user-assisted remote attackers to execute arbitrary VBA code via a crafted map (.mxd) file.
References
Link | Resource |
---|---|
http://packetstormsecurity.org/files/113644/ESRI-ArcMap-Arbitrary-Code-Execution.html | Exploit |
http://www.cs.umb.edu/~joecohen/exploits/CVE-2012-1661/ | Exploit |
http://www.exploit-db.com/exploits/19138 | Exploit Third Party Advisory VDB Entry |
http://www.osvdb.org/82986 | Broken Link |
http://www.securitytracker.com/id?1027170 | Exploit Third Party Advisory VDB Entry |
http://packetstormsecurity.org/files/113644/ESRI-ArcMap-Arbitrary-Code-Execution.html | Exploit |
http://www.cs.umb.edu/~joecohen/exploits/CVE-2012-1661/ | Exploit |
http://www.exploit-db.com/exploits/19138 | Exploit Third Party Advisory VDB Entry |
http://www.osvdb.org/82986 | Broken Link |
http://www.securitytracker.com/id?1027170 | Exploit Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2012-07-12 21:55
Updated : 2025-04-11 00:51
NVD link : CVE-2012-1661
Mitre link : CVE-2012-1661
CVE.ORG link : CVE-2012-1661
JSON object : View
Products Affected
esri
- arcmap
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')