Impact
ImageMagick versions prior to 6.9.13‑56 and 7.x before 7.1.2‑31 allow a policy bypass when a policy uses a coder domain instead of a module domain, enabling an attacker to supply a crafted image that causes the software to process file formats that an administrator intended to block. The CVSS score of 6.9 indicates moderate severity, and the EPSS score is not available. Because the security policy is respected only after image parsing, the vulnerability can lead to processing of malicious image formats that could lead to code execution if those formats invoke arbitrary code execution handlers. The impact therefore ranges from inadvertent processing of disallowed formats to potential execution of attacker‑controlled code, depending on the policies active in the environment.
Affected Systems
Any system running ImageMagick that has not applied the official update to at least 6.9.13‑56 or 7.1.2‑31 is affected. The vulnerability is present in the ImageMagick core product; administrators should review all deployments using ImageMagick for image processing, ad‑hoc scripts, web applications, or other services that invoke the ImageMagick library.
Risk and Exploitability
The CVSS score of 6.9 places the vulnerability in the moderate range, but because no EPSS value is provided the likelihood of exploitation is unclear. The vulnerability is not yet listed in the CISA KEV catalog, which reduces the urgency but does not eliminate risk. The likely attack vector is remote: an attacker can send a crafted image through a web upload or other interface that internally calls ImageMagick. If the system relies on coder‑based policies, the attacker can bypass those restrictions, causing ImageMagick to process the previously blocked format and potentially execute embedded code or otherwise compromise the host.
OpenCVE Enrichment