High severity7.8NVD Advisory· Published May 5, 2021· Updated Jun 17, 2026
CVE-2021-29100
CVE-2021-29100
Description
A path traversal vulnerability exists in Esri ArcGIS Earth versions 1.11.0 and below which allows arbitrary file creation on an affected system through crafted input. An attacker could exploit this vulnerability to gain arbitrary code execution under security context of the user running ArcGIS Earth by inducing the user to upload a crafted file to an affected system.
Affected products
3cpe:2.3:a:esri:arcgis_earth:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:esri:arcgis_earth:*:*:*:*:*:*:*:*range: <=1.11.0
- (no CPE)range: <=1.11.0
- (no CPE)range: 1.11
Patches
Vulnerability mechanics
References
1- www.esri.com/arcgis-blog/products/arcgis-earth/administration/arcgis-earth-security-updatenvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.