Security Advisory
CVE-2021-29095
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Multiple uninitialized pointer vulnerabilities when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticated attacker with specialized permissions to achieve arbitrary code execution in the context of the service account.