EDB-ID: 19138 CVE: 2012-1661 Author: BOSTON CYBER DEFENSE Type: LOCAL Platform: WINDOWS Date: 2012-06-14 Vulnerable App: ESRI ArcMap 9 / ArcGIS Desktop 10 Description: Opening a specially crafted mxd file will execute arbitrary code without prompting and without a crash of the application. This is due to a flaw in the program's ability to prompt a user before executing embedded VBA. Mxd files are not filtered by email systems, allowing a remote attacker to trick a user into opening a map file via email and unknowingly gain control over their system. Versions Affected: ArcMap 9 ArcGIS Desktop 10 Release Version: 10.0 Product Version: 10.0.1.2800 ArcGIS Service Pack: 0.1 (build 10.0.1.2800) ArcGIS Desktop 10 Release Version: 10.0 Product Version: 10.0.2.3200 ArcGIS Service Pack: 2 (build 10.0.2.3200) Proof of Concept: A macro can be implemented in the project to execute Shell statements when the document is opened without prompt. Video at site: http://www.cs.umb.edu/~joecohen/exploits/CVE-2012-1661