CVE-2021-29093: ArcGIS Server image service and raster analytics security update: use-after-free
Published Mar 25, 2021
·Updated
A use-after-free vulnerability when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticated attacker with specialized permissions to achieve arbitrary code execution in the context of the service account.
Affected Software
2 affected components
Esri ArcGIS<=10.8.1
Esri ArcGIS Server<=10.8.1
Event History
Mar 25, 2021
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-29093?
CVE-2021-29093 has a high severity rating due to its potential for arbitrary code execution.
2
How do I fix CVE-2021-29093?
To mitigate CVE-2021-29093, upgrade Esri ArcGIS Server to version 10.8.2 or later.
3
Who is affected by CVE-2021-29093?
CVE-2021-29093 affects authenticated users with specialized permissions in Esri ArcGIS Server 10.8.1 and earlier versions.
4
What type of vulnerability is CVE-2021-29093?
CVE-2021-29093 is classified as a use-after-free vulnerability.
5
What can an attacker do with CVE-2021-29093?
An attacker exploiting CVE-2021-29093 can achieve arbitrary code execution within the context of the service account.