A use-after-free vulnerability when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticated attacker with specialized permissions to achieve arbitrary code execution in the context of the service account.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Esri
Published: 2021-03-25T20:32:06.303691Z
Updated: 2024-09-17T02:01:25.468Z
Reserved: 2021-03-23T00:00:00
Link: CVE-2021-29093
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-03-25T21:15:13.167
Modified: 2024-11-21T06:00:42.043
Link: CVE-2021-29093
Redhat
No data.