CVE-2012-1661
ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, which allows user-assisted remote attackers to execute arbitrary VBA code via a crafted map (.mxd) file.
Date published : 2012-07-12
http://www.exploit-db.com/exploits/19138
http://packetstormsecurity.org/files/113644/ESRI-ArcMap-Arbitrary-Code-Execution.html