There is an untrusted search path vulnerability in Esri ArcGIS AllSource 1.2 and 1.3 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a specific action using ArcGIS AllSource, the file could execute and run malicious commands under the context of the victim. This issue is corrected in ArcGIS AllSource 1.2.1 and 1.3.1.
History

Tue, 04 Mar 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Esri
Esri arcgis Allsource
Esri arcgis Pro
CPEs cpe:2.3:a:esri:arcgis_allsource:1.2:-:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_allsource:1.3:-:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_pro:3.3:-:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_pro:3.4:-:*:*:*:*:*:*
Vendors & Products Esri
Esri arcgis Allsource
Esri arcgis Pro

Wed, 26 Feb 2025 00:00:00 +0000

Type Values Removed Values Added
Description There is an untrusted search path vulnerability in Esri ArcGIS AllSource 1.2 and 1.3 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a specific action using ArcGIS AllSource, the file could execute and run malicious commands under the context of the victim. There is an untrusted search path vulnerability in Esri ArcGIS AllSource 1.2 and 1.3 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a specific action using ArcGIS AllSource, the file could execute and run malicious commands under the context of the victim. This issue is corrected in ArcGIS AllSource 1.2.1 and 1.3.1.

Tue, 25 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Feb 2025 16:45:00 +0000

Type Values Removed Values Added
Description There is an untrusted search path vulnerability in Esri ArcGIS AllSource 1.2 and 1.3 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a specific action using ArcGIS AllSource, the file could execute and run malicious commands under the context of the victim.
Title There is a code injection vulnerability in Esri ArcGIS AllSource
Weaknesses CWE-426
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Esri

Published: 2025-02-25T16:26:18.161Z

Updated: 2025-02-26T00:05:24.143Z

Reserved: 2025-02-05T18:59:51.831Z

Link: CVE-2025-1068

cve-icon Vulnrichment

Updated: 2025-02-25T16:46:32.086Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-25T17:15:13.890

Modified: 2025-03-04T17:22:39.620

Link: CVE-2025-1068

cve-icon Redhat

No data.