Impact
ImageMagick implementations prior to version 6.9.13-56 and 7.x prior to 7.1.2-31 contain a missing security policy check in the CUT encoder. This flaw permits an attacker to supply specially crafted input processed by the CUT encoder to either crash the application or expose sensitive information that the policy would normally have prevented. The vulnerability is a form of over‑privileged operation and could be used to compromise the confidentiality or availability of systems that process untrusted image data.
Affected Systems
The issue affects ImageMagick’s core product. Versions before 6.9.13-56 and before 7.1.2-31 of the 7.x release series are affected. Any installation of these versions that uses the CUT encoder is vulnerable; secure or restricted deployments that disable this encoder are not at risk.
Risk and Exploitability
The published CVSS score of 2.1 indicates low severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Based on the description, exploitation requires an attacker to deliver malicious input that is processed through the CUT encoder. The likely attack vector is that an attacker could supply crafted images to any service that calls the CUT encoder to process the image, which could be in typical image‑processing pipelines or web services that accept user‑supplied images. Inferred from the description, the attacker does not need local privileges and remote exploitation is plausible if the ImageMagick instance is exposed through a network service.
OpenCVE Enrichment