ArcGIS general raster security update: uninitialized pointer
No sign of exploitation. No public exploitation artifact known so far.
ArcGIS products contain uninitialized pointer bugs that can be triggered by opening a malicious file, allowing attackers to run arbitrary code on the victim's computer without authentication.
Multiple uninitialized pointer vulnerabilities exist in raster file parsing across ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 and earlier, and ArcGIS Pro 2.7 and earlier. An unauthenticated attacker can craft a specially designed raster file to exploit these memory corruption flaws, achieving arbitrary code execution with the privileges of the current user. No prior authentication or special privileges are required; exploitation requires only convincing a user to open the malicious file.