CVE-2021-29117

HIGH

Esri ArcReader < 10.8.1 - Use-After-Free via Crafted File Parsing

Title source: llm
STIX 2.1

Description

A use-after-free vulnerability when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) allows an unauthenticated attacker to achieve arbitrary code execution in the context of the current user.

Scores

CVSS v3 7.8
EPSS 0.0005
EPSS Percentile 15.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-416
Status published
Products (1)
esri/arcreader < 10.8.1
Published Aug 12, 2022
Tracked Since Feb 18, 2026