Impact
ImageMagick contains a flaw that allows a crafted local encoding operation to bypass internal security policy checks in the CUT encoder. This permits the attacker to read data that policy should forbid and can also trigger an application crash. The weakness is a breach of least privilege, leading to unauthorized information disclosure and possible denial of service, as indicated by the CWE-284 and CWE-400 identifiers.
Affected Systems
The affected products are ImageMagick versions prior to 7.1.2-31 and 6.9.13-56. Any installations running these earlier releases are susceptible to the policy bypass in the CUT encoder.
Risk and Exploitability
The CVSS score is 4, indicating medium severity. No EPSS score is available, and the vulnerability is not listed in CISA KEV. The likely attack vector is a local crafted encoding operation performed by a user who can input data to the CUT encoder. If the attacker can execute such an operation, they may read restricted data or cause a crash, both of which can lead to system instability or leakage of sensitive information.
OpenCVE Enrichment