CVSS v3.1 Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Prediction
Documented as more likely to be exploited than 99.8% of known CVEs.
Sep 09, 2024
Sep 30, 2024
Threat Analysis
ImageMagick contains an improper input validation vulnerability that affects the EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, and PLT coders. This allows a remote attacker to execute arbitrary code via shell metacharacters in a crafted image.
Remediation Directive
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
External Intelligence
This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see:
https://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=29588#p132726,
National Vulnerability Database
https://nvd.nist.gov/vuln/detail/CVE-2016-3714