← back
CVE-2021-29097highCWE-121CWE-122

ArcGIS general raster security update: buffer overflow

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.8epss 2.4%
exploitation probability
2.4%top 17% of all CVEs
observed exploitation
nono source reports it
In short

ArcGIS and ArcReader contain buffer overflow flaws when processing specially crafted raster files. An attacker can send a malicious file to execute arbitrary code on the victim's computer.

Technical detail

Multiple stack and heap buffer overflows exist in raster file parsing across ArcGIS Desktop, ArcGIS Engine 10.8.1 and earlier, ArcGIS Pro 2.7 and earlier, and ArcReader. An unauthenticated attacker can exploit these by providing a specially crafted file, leading to arbitrary code execution with user privileges; no authentication or user interaction restrictions are specified beyond file opening.

Summary generated and translated by AI from the official description.
Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) and ArcGIS Pro 2.7 (and earlier) allow an unauthenticated attacker to achieve arbitrary code execution in the context of the current user.
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H