The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability.
https://exchange.xforce.ibmcloud.com/vulnerabilities/3155
https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-030