Use-after-free in ArcReader - CVE-2021-29117
Published: February 7, 2022
ArcReader
ESRI
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the parsing of PMF files. A remote attacker can trick a victim to a specially crafted PMF file and execute arbitrary code on the system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.