Impact
This vulnerability allows an attacker to craft an XMP profile that causes ImageMagick to terminate unexpectedly instead of throwing an exception. When the application processes a malicious image, the ImageMagick library crashes, leading to a denial of service that can disrupt processing pipelines or web services that rely on image manipulation.
Affected Systems
It affects ImageMagick releases prior to 6.9.13‑55 and 7.x prior to 7.1.2‑30. Systems that embed the ImageMagick library for image conversion, thumbnail generation, or other processing tasks are at risk if they use those vulnerable versions.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. Because the exploit requires delivery of a crafted image to the target application, the attack vector is likely local or through any interface that accepts image uploads. The EPSS score is not available and the vulnerability is not listed in CISA KEV, but the potential for repeated crashes suggests a valuable target for denial of service campaigns.
OpenCVE Enrichment