← back
CVE-2021-29096highCWE-416

ArcGIS general raster security update: use-after-free

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.8epss 1.5%
exploitation probability
1.5%top 27% of all CVEs
observed exploitation
nono source reports it
In short

A memory flaw in ArcGIS applications allows an attacker to run malicious code on your computer by sending a specially crafted file. Once you open the file, the attacker gains the same access and permissions as you.

Technical detail

Use-after-free vulnerability in raster file parsing across ArcReader, ArcGIS Desktop, ArcGIS Engine ≤10.8.1, and ArcGIS Pro ≤2.7. Unauthenticated remote code execution is achieved through a maliciously crafted file that triggers access to freed memory, enabling arbitrary code execution within the current user's context.

Summary generated and translated by AI from the official description.
A use-after-free vulnerability when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) and ArcGIS Pro 2.7 (and earlier) allows an unauthenticated attacker to achieve arbitrary code execution in the context of the current user.
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H