CVE-2021-29094: ArcGIS Server image service and raster analytics security update: buffer overflow
Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticated attacker with specialized permissions to achieve arbitrary code execution in the context of the service account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-29094?
CVE-2021-29094 is rated as a critical severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2021-29094?
To fix CVE-2021-29094, update Esri ArcGIS Server to version 10.9 or later.
Who is affected by CVE-2021-29094?
CVE-2021-29094 affects authenticated users of Esri ArcGIS Server versions 10.8.1 and earlier.
What type of attack is possible with CVE-2021-29094?
CVE-2021-29094 allows an authenticated attacker to execute arbitrary code in the context of the service account.
Is CVE-2021-29094 a local or remote vulnerability?
CVE-2021-29094 is considered a local vulnerability because it requires authenticated access to exploit.