There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a specific action using ArcGIS ArcGIS Pro, the file could execute and run malicious commands under the context of the victim. This issue is addressed in ArcGIS Pro 3.3.3 and 3.4.1.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Mar 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Esri
Esri arcgis Allsource Esri arcgis Pro |
|
CPEs | cpe:2.3:a:esri:arcgis_allsource:1.2:-:*:*:*:*:*:* cpe:2.3:a:esri:arcgis_allsource:1.3:-:*:*:*:*:*:* cpe:2.3:a:esri:arcgis_pro:3.3:-:*:*:*:*:*:* cpe:2.3:a:esri:arcgis_pro:3.4:-:*:*:*:*:*:* |
|
Vendors & Products |
Esri
Esri arcgis Allsource Esri arcgis Pro |
Wed, 26 Feb 2025 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a specific action using ArcGIS ArcGIS Pro, the file could execute and run malicious commands under the context of the victim. | There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a specific action using ArcGIS ArcGIS Pro, the file could execute and run malicious commands under the context of the victim. This issue is addressed in ArcGIS Pro 3.3.3 and 3.4.1. |
Wed, 26 Feb 2025 00:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a specific action using ArcGIS ArcGIS Pro , the file could execute and run malicious commands under the context of the victim. | There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a specific action using ArcGIS ArcGIS Pro, the file could execute and run malicious commands under the context of the victim. |
Tue, 25 Feb 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 25 Feb 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a specific action using ArcGIS ArcGIS Pro , the file could execute and run malicious commands under the context of the victim. | |
Title | There is a code injection vulnerability in ArcGIS Pro | |
Weaknesses | CWE-732 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Esri
Published: 2025-02-25T16:26:03.580Z
Updated: 2025-02-26T00:03:50.613Z
Reserved: 2025-02-05T18:48:27.690Z
Link: CVE-2025-1067

Updated: 2025-02-25T16:46:06.469Z

Status : Analyzed
Published: 2025-02-25T17:15:13.717
Modified: 2025-03-04T17:22:39.620
Link: CVE-2025-1067

No data.