← back
CVE-2021-29098highCWE-824

ArcGIS general raster security update: uninitialized pointer

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.8epss 2.0%
exploitation probability
2.0%top 21% of all CVEs
observed exploitation
nono source reports it
In short

ArcGIS products contain uninitialized pointer bugs that can be triggered by opening a malicious file, allowing attackers to run arbitrary code on the victim's computer without authentication.

Technical detail

Multiple uninitialized pointer vulnerabilities exist in raster file parsing across ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 and earlier, and ArcGIS Pro 2.7 and earlier. An unauthenticated attacker can craft a specially designed raster file to exploit these memory corruption flaws, achieving arbitrary code execution with the privileges of the current user. No prior authentication or special privileges are required; exploitation requires only convincing a user to open the malicious file.

Summary generated and translated by AI from the official description.
Multiple uninitialized pointer vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) and ArcGIS Pro 2.7 (and earlier) allow an unauthenticated attacker to achieve arbitrary code execution in the context of the current user.
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H