Vulnonym.com

CVE-2012-1661 - In and in Cemetery

Description

ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros which allows user-assisted remote attackers to execute arbitrary VBA code via a crafted map (.mxd) file.

Reference

http://packetstormsecurity.org/files/113644/ESRI-ArcMap-Arbitrary-Code-Execution.html http://www.osvdb.org/82986 http://www.securitytracker.com/id?1027170 http://www.exploit-db.com/exploits/19138 http://www.cs.umb.edu/~joecohen/exploits/CVE-2012-1661/