7.8

CVE-2021-29098

ArcGIS general raster security update: uninitialized pointer

Multiple uninitialized pointer vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) and ArcGIS Pro 2.7 (and earlier) allow an unauthenticated attacker to achieve arbitrary code execution in the context of the current user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EsriArcgis Engine Version <= 10.8.1
EsriArcgis Pro Version <= 2.7
EsriArcmap Version <= 10.8.1
EsriArcreader Version <= 10.8.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.95% 0.776
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
psirt@esri.com 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-824 Access of Uninitialized Pointer

The product accesses or uses a pointer that has not been initialized.

https://www.esri.com/arcgis-blog/products/arcgis/administration/security-advisory-general-raster/
Vendor Advisory
https://www.zerodayinitiative.com/advisories/ZDI-21-361/
Third Party Advisory
VDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-21-362/
Third Party Advisory
VDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-21-372/
Third Party Advisory
VDB Entry