Executive brief
ArcGIS Server, a mapping and geospatial data platform used by organizations worldwide, contains a vulnerability that allows unauthenticated attackers to upload arbitrary files to the server. Although the server's architecture restricts uploaded files to non-executable locations and prevents code execution or privilege escalation, the ability to upload arbitrary files could enable information disclosure attacks or be chained with other issues in certain specialized conditions.
Technical details
The vulnerability is an arbitrary file upload flaw caused by insufficient validation of uploaded files in ArcGIS Server versions 11.5 and earlier. An unauthenticated attacker can send a crafted request to upload files to the server's designated upload directories without proper file-type or content verification. The server's architecture provides inherent protection by storing uploads in non-executable locations and enforcing access controls that prevent execution, privilege escalation, or modification of system components. However, the unrestricted upload capability could potentially be exploited in specialized attack scenarios requiring race conditions, knowledge of secret values, or man-in-the-middle interference to achieve information disclosure or other limited impacts.
Affected products
- Esri ArcGIS Server 11.5 and earlier
Timeline
- 2025-12-31: disclosed