CVE-2025-1067

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Feb 25, 2025
Updated: Mar 4, 2025
CWE ID 732

Summary

CVE-2025-1067 is an untrusted search path vulnerability affecting Esri ArcGIS Pro 3.3 and 3.4. A low privileged attacker with write access to the local file system can exploit this issue by introducing a malicious executable. Upon execution of a specific action in ArcGIS Pro, the malicious file can run with the victim's context, potentially leading to command execution. This vulnerability is resolved in ArcGIS Pro 3.3.3 and 3.4.1.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share