CVE-2021-29117: arcreader use-after-free
Published Aug 12, 2022
·Updated
A use-after-free vulnerability when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) allows an unauthenticated attacker to achieve arbitrary code execution in the context of the current user.
Affected Software
1 affected component
Esri ArcReader<=10.8.1
Event History
Aug 12, 2022
CVE Published
via MITRE·06:45 PM
Data Sourced
via MITRE·06:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-29117?
The severity of CVE-2021-29117 is high with a CVSS score of 7.8.
2
How does CVE-2021-29117 affect Esri ArcReader?
CVE-2021-29117 affects Esri ArcReader version 10.8.1 and earlier.
3
What is the impact of CVE-2021-29117?
CVE-2021-29117 allows an unauthenticated attacker to achieve arbitrary code execution in the context of the current user.
4
Is CVE-2021-29117 exploitable remotely?
Yes, CVE-2021-29117 can be exploited remotely by an unauthenticated attacker.
5
How can I mitigate the vulnerability in Esri ArcReader?
To mitigate CVE-2021-29117, it is recommended to update Esri ArcReader to the latest version available.