CVE-2024-51966

CVSS 3.1 Score 4.9 of 10 (medium)

Attack Complexity low
Confidentiality high
Privileges Required high
Integrity none
Availability none
Scope unchanged

Details

Published Mar 3, 2025
Updated: Mar 6, 2025
CWE ID 22

Summary

CVE-2024-51966 is a path traversal vulnerability affecting ESRI ArcGIS Server versions 10.9.1 to 11.3. This issue enables a remote, authenticated attacker with administrative privileges to bypass intended file access restrictions and navigate the file system. Although there is no reported impact on system integrity or availability, the confidentiality of certain files could be at risk due to the vulnerability. Successful exploitation could lead to unauthorized access to sensitive information. Organizations using the affected versions are advised to apply the necessary patches promptly to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share