CVE-2025-1067
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published Feb 25, 2025
Updated: Mar 4, 2025
CWE ID 732
Summary
CVE-2025-1067 is an untrusted search path vulnerability affecting Esri ArcGIS Pro 3.3 and 3.4. A low privileged attacker with write access to the local file system can exploit this issue by introducing a malicious executable. Upon execution of a specific action in ArcGIS Pro, the malicious file can run with the victim's context, potentially leading to command execution. This vulnerability is resolved in ArcGIS Pro 3.3.3 and 3.4.1.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- ArcGIS Pro
Affected Vendors
- Esri