VYPR
High severity7.8NVD Advisory· Published Mar 25, 2021· Updated Jun 17, 2026

CVE-2021-29097

CVE-2021-29097

Description

Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) and ArcGIS Pro 2.7 (and earlier) allow an unauthenticated attacker to achieve arbitrary code execution in the context of the current user.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

13
  • Esri/Arcgis For Desktopcpe-rescue2 versions
    All+ 1 more
    • (no CPE)range: All
    • (no CPE)range: <=10.8.1
  • Esri/Arcgis For Enginecpe-rescue2 versions
    All+ 1 more
    • (no CPE)range: All
    • (no CPE)range: <=10.8.1
  • Esri/Arcgis Procpe-rescue3 versions
    All+ 2 more
    • (no CPE)range: All
    • (no CPE)range: <=2.7
    • cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*range: <=2.7
  • Esri/ArcReadercpe-rescue3 versions
    All+ 2 more
    • (no CPE)range: All
    • (no CPE)
    • cpe:2.3:a:esri:arcreader:*:*:*:*:*:*:*:*range: <=10.8.1
  • Esri/ArcGIS Desktop Background Geoprocessingv5
    Range: All
  • cpe:2.3:a:esri:arcgis_engine:*:*:*:*:*:*:*:*
    Range: <=10.8.1
  • cpe:2.3:a:esri:arcmap:*:*:*:*:*:*:*:*
    Range: <=10.8.1

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.