Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ergod

Researcher fromTrend Micro Zero Day Initiative
#40046of 53,624
6.8Total CVSS
Vulnerabilities · 1
PT-2021-18083
6.8
2021-03-25
Esri · Esri Arcgis Server · CVE-2021-29095
Name of the Vulnerable Software and Affected Versions: Esri ArcGIS Server versions 10.8.1 and earlier Description: The issue arises from multiple uninitialized pointer vulnerabilities when parsing a specially crafted file. This allows an authenticated attacker with specialized permissions to achieve arbitrary code execution in the context of the service account. Recommendations: For Esri ArcGIS Server versions 10.8.1 and earlier, update to a version that addresses the uninitialized pointer vulnerabilities to prevent arbitrary code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.