← Vulnerability feed

Vulnerability record · CVE-2021-29098 · published 25 March 2021

CVE-2021-29098: Esri arcgis engine vulnerability

Esri · Arcgis Engine

Multiple uninitialized pointer vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) and ArcGIS Pro 2.7 (and earlier) allow an unauthenticated attacker to achieve arbitrary code execution in the context of the current user.

7.8 CVSS 3.1 High EPSS 2.0% · top 20.6% CWE-824 · CWE-824
7.8CVSS 3.1 base score, v2 6.8
2.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Multiple uninitialized pointer vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) and ArcGIS Pro 2.7 (and earlier) allow an unauthenticated attacker to achieve arbitrary code execution in the context of the current user.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-29098 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2012-1661Esri arcmap code injection vulnerabilityESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, which allows user-assisted remo…EPSS 24%7.8CVE-2021-29117Esri arcreader use after free vulnerabilityA use-after-free vulnerability when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) allows an unauthenticated attacker to ach…EPSS 0.44%7.8CVE-2021-29097Esri arcgis engine stack-based buffer overflow vulnerabilityMultiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) …EPSS 2.4%7.8CVE-2021-29096Esri arcgis engine use after free vulnerabilityA use-after-free vulnerability when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) and ArcGIS…EPSS 1.5%7.3CVE-2025-1067Esri arcgis allsource incorrect permission assignment vulnerabilityThere is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to the …EPSS 0.19%7.3CVE-2025-1068Esri arcgis allsource untrusted search path vulnerabilityThere is an untrusted search path vulnerability in Esri ArcGIS AllSource 1.2 and 1.3 that may allow a low privileged attacker with write privileges t…EPSS 0.22%5.5CVE-2021-29118Esri arcreader out-of-bounds read vulnerabilityAn out-of-bounds read vulnerability exists when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) which allow an unauthenticate…EPSS 0.35%5.5CVE-2021-29112Esri arcreader out-of-bounds read vulnerabilityAn out-of-bounds read vulnerability exists when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) which allow an unauthenticate…EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2021-29098), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.