The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability.
No PoCs from references.
- https://github.com/ARPSyndicate/cve-scores