There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a specific action using ArcGIS ArcGIS Pro, the file could execute and run malicious commands under the context of the victim. This issue is addressed in ArcGIS Pro 3.3.3 and 3.4.1.
Conclusion & alert: CVE-2025-1067 is rated Moderate Risk (43.1/100): CVSS High severity, with low exploitation likelihood (EPSS 0.18%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-05 | 0.04% | 0.18% | +0.13% |
| 2 | 2025-02-27 | — | 0.04% | — |
Full EPSS history (2 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.3 | 3.1 | HIGH |
|
1.3 | 5.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| esri | arcgis_allsource | 1.2 | cpe:2.3:a:esri:arcgis_allsource:1.2:*:*:*:*:*:*:* |
| esri | arcgis_allsource | 1.3 | cpe:2.3:a:esri:arcgis_allsource:1.3:*:*:*:*:*:*:* |
| esri | arcgis_pro | 3.3 | cpe:2.3:a:esri:arcgis_pro:3.3:*:*:*:*:*:*:* |
| esri | arcgis_pro | 3.4 | cpe:2.3:a:esri:arcgis_pro:3.4:*:*:*:*:*:*:* |