Unrated severityNVD Advisory· Published Jul 12, 2012· Updated Apr 29, 2026
CVE-2012-1661
CVE-2012-1661
Description
ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, which allows user-assisted remote attackers to execute arbitrary VBA code via a crafted map (.mxd) file.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- packetstormsecurity.org/files/113644/ESRI-ArcMap-Arbitrary-Code-Execution.htmlnvdExploit
- www.cs.umb.edu/~joecohen/exploits/CVE-2012-1661/nvdExploit
- www.exploit-db.com/exploits/19138nvdExploitThird Party AdvisoryVDB Entry
- www.securitytracker.com/idnvdExploitThird Party AdvisoryVDB Entry
- www.osvdb.org/82986nvdBroken Link
News mentions
0No linked articles in our index yet.