Impact
ImageMagick versions prior to 7.1.2-32 and 6.9.13-57 contain a vulnerability in the LoadPolicyCache function that allows an attacker to supply a policy.xml file with an alternate DOCTYPE. The parser incorrectly handles a DOCTYPE that does not terminate with "]>", causing it to consume the remainder of the file and silently skip all defined security policy rules. As a result, operations that are normally restricted by the policy become allowed, creating a clear path for an attacker to perform unintended actions such as accessing or modifying files, executing commands, or otherwise violating the intended security posture.
Affected Systems
The affected vendor is ImageMagick and the product is ImageMagick. Versions affected are all releases prior to 7.1.2-32 and all releases prior to 6.9.13-57, meaning almost all older releases of the software are susceptible unless upgraded.
Risk and Exploitability
The CVSS score of 1.8 places this issue in the low severity range, and the EPSS score is not documented, indicating a low exploitation probability as of the latest data. It is not listed in the CISA KEV catalog. The vulnerability is likely to be exploited locally by an attacker who can influence image processing via a crafted policy.xml file, though remote exploitation could be possible if an untrusted image is processed by a publicly exposed service. The evidence available suggests the attack vector is not high and the impact is limited to policy-bypass rather than direct remote code execution.
OpenCVE Enrichment