CVE-2007-1770

ESRI ArcSDE - Buffer Overflow via Long Parameters in Three-Tiered Configurations

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-1770. PoCs published by Heretic2.

AI-analyzed exploit summary This exploit targets a stack-based buffer overflow in ESRI ArcSDE 9.0-9.2sp1, allowing remote code execution by overwriting EIP and executing shellcode. It includes multiple return addresses for different versions and languages, and supports both bind and reverse shells.

Description

Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Service Pack 2, when using three tiered ArcSDE configurations, allows remote attackers to cause a denial of service (giomgr crash) and execute arbitrary code via long parameters in crafted requests.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Heretic2 · c++remotewindows
https://www.exploit-db.com/exploits/4146

This exploit targets a stack-based buffer overflow in ESRI ArcSDE 9.0-9.2sp1, allowing remote code execution by overwriting EIP and executing shellcode. It includes multiple return addresses for different versions and languages, and supports both bind and reverse shells.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: ESRI ArcSDE 9.0 - 9.2sp1
No auth needed
Prerequisites: Network access to the vulnerable ArcSDE service · Knowledge of target OS and ArcSDE version for correct return address selection
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1017874
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/23175
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/33457
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/24639
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/33282
Broken Link third-party-advisory x_refsource_idefense
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=507
Broken Link, Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1140

Scores

EPSS 0.2660
EPSS Percentile 96.5%

Details

CWE
CWE-120
Status published
Products (3)
esri/arcsde 8.3 (2 CPE variants)
esri/arcsde 9.0 (3 CPE variants)
esri/arcsde 9.1 (3 CPE variants)
Published Mar 30, 2007
Tracked Since Feb 18, 2026