CVE-2025-1067
There is a code injection vulnerability in ArcGIS Pro
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a specific action using ArcGIS ArcGIS Pro, the file could execute and run malicious commands under the context of the victim. This issue is addressed in ArcGIS Pro 3.3.3 and 3.4.1.
There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a specific action using ArcGIS ArcGIS Pro, the file could execute and run malicious commands under the context of the victim. This issue is addressed in ArcGIS Pro 3.3.3 and 3.4.1.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2025-02-05 CVE Reserved
- 2025-02-25 CVE Published
- 2025-02-26 CVE Updated
- 2025-03-29 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-732: Incorrect Permission Assignment for Critical Resource
CAPEC
- CAPEC-558: Replace Trusted Executable
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Esri Search vendor "Esri" | ArcGIS Pro Search vendor "Esri" for product "ArcGIS Pro" | >= 3.3.0 <= 3.3.2 Search vendor "Esri" for product "ArcGIS Pro" and version " >= 3.3.0 <= 3.3.2" | en |
Affected
| ||||||
Esri Search vendor "Esri" | ArcGIS Pro Search vendor "Esri" for product "ArcGIS Pro" | 3.4.0 Search vendor "Esri" for product "ArcGIS Pro" and version "3.4.0" | en |
Affected
|