First published: Thu Jul 12 2012(Updated: )
ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, which allows user-assisted remote attackers to execute arbitrary VBA code via a crafted map (.mxd) file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Esri ArcGIS | <=10.0.2.3200 | |
Esri ArcGIS | =9.0 | |
ESRI ArcMap | =9.0 | |
ESRI ArcMap | <=10.0.2.3200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1661 has been classified as a high severity vulnerability due to the potential for arbitrary code execution.
To fix CVE-2012-1661, users should upgrade to a version of Esri ArcGIS or ArcMap that is above 10.0.2.3200.
CVE-2012-1661 affects ESRI ArcMap version 9.0 and ArcGIS versions up to and including 10.0.2.3200.
CVE-2012-1661 allows user-assisted remote attackers to execute arbitrary VBA code via a crafted .mxd map file.
Yes, CVE-2012-1661 requires user interaction to execute the vulnerable VBA macros.