ArcGIS Server image service and raster analytics security update: use-after-free
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.4epss 0.9%
exploitation probability
0.9%top 41% of all CVEs
observed exploitation
nono source reports it
In short
A memory error in ArcGIS Server allows an authenticated attacker with special permissions to run malicious code by uploading a specially crafted file. The flaw exists because the software tries to use memory that has already been freed.
Technical detail
Use-after-free vulnerability in ArcGIS Server 10.8.1 and earlier triggered during file parsing. Attack vector requires authentication and specialized permissions; successful exploitation results in arbitrary code execution with service account privileges. The vulnerability stems from improper memory management of parsed file data.
Summary generated and translated by AI from the official description.
A use-after-free vulnerability when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticated attacker with specialized permissions to achieve arbitrary code execution in the context of the service account.
CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Affected products
Esri · ArcGIS Server