CVE-2021-29100
ArcGIS Earth has a File Parsing Directory Traversal Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A path traversal vulnerability exists in Esri ArcGIS Earth versions 1.11.0 and below which allows arbitrary file creation on an affected system through crafted input. An attacker could exploit this vulnerability to gain arbitrary code execution under security context of the user running ArcGIS Earth by inducing the user to upload a crafted file to an affected system.
Se presenta una vulnerabilidad de salto de ruta en Esri ArcGIS Earth versiones 1.11.0 y anteriores, que permite la creación de archivos arbitrarios en un sistema afectado por medio de una entrada diseñada. Un atacante podría explotar esta vulnerabilidad para obtener una ejecución de código arbitraria en el contexto de seguridad del usuario que ejecuta ArcGIS Earth al inducir al usuario a cargar un archivo diseñado en un sistema afectado
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Esri ArcGIS Earth. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of KMZ files. When handling filenames specified within a KMZ file, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-03-23 CVE Reserved
- 2021-05-03 CVE Published
- 2024-09-16 CVE Updated
- 2024-10-08 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-23: Relative Path Traversal
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Esri Search vendor "Esri" | Arcgis Earth Search vendor "Esri" for product "Arcgis Earth" | <= 1.11.0 Search vendor "Esri" for product "Arcgis Earth" and version " <= 1.11.0" | - |
Affected
|