Impact
ImageMagick prior to version 7.1.2-24 implements a policy check that is insufficiently validated, enabling attackers to create or truncate files that should be protected by security policies. This flaw permits the writing of arbitrary files outside the intended directory boundaries, potentially allowing persistent access, configuration manipulation, or installation of malicious payloads. The weakness is a classic path traversal error (CWE‑22), which undermines confidentiality, integrity, and availability of the affected system.
Affected Systems
The vulnerability affects all installations of the ImageMagick image processing library with versions earlier than 7.1.2-24. Any system running this component, regardless of operating environment, is susceptible when the library is exposed to external input via sandboxed conversion services.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate risk, while the EPSS score is not available, suggesting no publicly reported exploitation prevalence. The flaw is listed as not present in the CISA KEV catalog. Attackers can exploit the issue remotely through image conversion services that accept user-supplied files; the exploitation requires the ability to submit files to the vulnerable image conversion process.
OpenCVE Enrichment
Debian DLA
Debian DSA