Home / Vulnerabilities / CVE-2016-3715
MEDIUM SEVERITY
CVE-2016-3715 ImageMagick · ImageMagick

ImageMagick Arbitrary File Deletion Vulnerability

Technical Severity

CVSS v3.1 Metrics

MEDIUM
5.5 / 10
Minimal Risk Critical
Vector Specification
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Exploitation Likelihood

EPSS Prediction

79.80 %
Predictive Probability
Percentile Rank
99.1 th

Documented as more likely to be exploited than 99.1% of known CVEs.

Detection Date

Nov 03, 2021

Remediation Due

May 03, 2022

CISA Catalog Active

Threat Analysis

ImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol, which deletes files after reading.

Remediation Directive

Apply updates per vendor instructions.

External Intelligence