There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a specific action using ArcGIS ArcGIS Pro, the file could execute and run malicious commands under the context of the victim. This issue is addressed in ArcGIS Pro 3.3.3 and 3.4.1.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-5364 There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a specific action using ArcGIS ArcGIS Pro, the file could execute and run malicious commands under the context of the victim. This issue is addressed in ArcGIS Pro 3.3.3 and 3.4.1.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 21 Jun 2025 05:45:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:esri:arcgis_allsource:1.2:-:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_allsource:1.3:-:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_pro:3.3:-:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_pro:3.4:-:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_allsource:1.2:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_allsource:1.3:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_pro:3.3:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_pro:3.4:*:*:*:*:*:*:*

Wed, 05 Mar 2025 03:00:00 +0900

Type Values Removed Values Added
First Time appeared Esri
Esri arcgis Allsource
Esri arcgis Pro
CPEs cpe:2.3:a:esri:arcgis_allsource:1.2:-:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_allsource:1.3:-:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_pro:3.3:-:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_pro:3.4:-:*:*:*:*:*:*
Vendors & Products Esri
Esri arcgis Allsource
Esri arcgis Pro

Wed, 26 Feb 2025 09:15:00 +0900

Type Values Removed Values Added
Description There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a specific action using ArcGIS ArcGIS Pro, the file could execute and run malicious commands under the context of the victim. There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a specific action using ArcGIS ArcGIS Pro, the file could execute and run malicious commands under the context of the victim. This issue is addressed in ArcGIS Pro 3.3.3 and 3.4.1.

Wed, 26 Feb 2025 09:00:00 +0900

Type Values Removed Values Added
Description There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a specific action using ArcGIS ArcGIS Pro , the file could execute and run malicious commands under the context of the victim. There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a specific action using ArcGIS ArcGIS Pro, the file could execute and run malicious commands under the context of the victim.

Wed, 26 Feb 2025 02:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Feb 2025 01:45:00 +0900

Type Values Removed Values Added
Description There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a specific action using ArcGIS ArcGIS Pro , the file could execute and run malicious commands under the context of the victim.
Title There is a code injection vulnerability in ArcGIS Pro
Weaknesses CWE-732
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Esri

Published:

Updated: 2025-02-26T00:03:50.613Z

Reserved: 2025-02-05T18:48:27.690Z

Link: CVE-2025-1067

cve-icon Vulnrichment

Updated: 2025-02-25T16:46:06.469Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-25T17:15:13.717

Modified: 2025-06-20T19:48:19.247

Link: CVE-2025-1067

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses