Junglewise Threat Intelligence

CVE-2025-67706: Esri ArcGIS Server arbitrary file upload on Windows and Linux

CVE-2025-67706 · Severity: medium · CVSS 5.6 · Published 2025-12-31

Technologies: Microsoft Windows, Esri ArcGIS Server, Linux Kernel. Vendors: Microsoft, Esri, Linux.

Executive brief

ArcGIS Server, a mapping and geospatial data platform used by organizations worldwide, contains a vulnerability that allows unauthenticated attackers to upload arbitrary files to the server. Although the server's architecture restricts uploaded files to non-executable locations and prevents code execution or privilege escalation, the ability to upload arbitrary files could enable information disclosure attacks or be chained with other issues in certain specialized conditions.

Technical details

The vulnerability is an arbitrary file upload flaw caused by insufficient validation of uploaded files in ArcGIS Server versions 11.5 and earlier. An unauthenticated attacker can send a crafted request to upload files to the server's designated upload directories without proper file-type or content verification. The server's architecture provides inherent protection by storing uploads in non-executable locations and enforcing access controls that prevent execution, privilege escalation, or modification of system components. However, the unrestricted upload capability could potentially be exploited in specialized attack scenarios requiring race conditions, knowledge of secret values, or man-in-the-middle interference to achieve information disclosure or other limited impacts.

Affected products

  • Esri ArcGIS Server 11.5 and earlier

Timeline

  • 2025-12-31: disclosed

References

Related threats