CVE-2012-1661: Code Injection
Published Jul 12, 2012
·Updated
ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, which allows user-assisted remote attackers to execute arbitrary VBA code via a crafted map (.mxd) file.
Affected Software
4 affected components
Esri ArcGIS<=10.0.2.3200
Esri ArcGIS=9.0
Esri ArcMap=9.0
Esri ArcMap<=10.0.2.3200
Event History
Jul 12, 2012
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-1661?
CVE-2012-1661 has been classified as a high severity vulnerability due to the potential for arbitrary code execution.
2
How do I fix CVE-2012-1661?
To fix CVE-2012-1661, users should upgrade to a version of Esri ArcGIS or ArcMap that is above 10.0.2.3200.
3
What are the affected versions in CVE-2012-1661?
CVE-2012-1661 affects ESRI ArcMap version 9.0 and ArcGIS versions up to and including 10.0.2.3200.
4
What kind of attack can be executed through CVE-2012-1661?
CVE-2012-1661 allows user-assisted remote attackers to execute arbitrary VBA code via a crafted .mxd map file.
5
Is user interaction required for CVE-2012-1661 to be exploited?
Yes, CVE-2012-1661 requires user interaction to execute the vulnerable VBA macros.