Impact
ImageMagick versions before 7.1.2-27 allow an attacker to trigger a heap buffer over-write by passing a specially crafted argument to the fx operation. This flaw can corrupt memory on the host and may lead to application instability or denial of service. The weakness is identified as CWE-787.
Affected Systems
The affected product is ImageMagick. All releases older than version 7.1.2‑27 are vulnerable.
Risk and Exploitability
The CVSS score of 5 indicates moderate severity, and the EPSS score of less than 1% suggests that the probability of exploitation is currently low. The vulnerability is not listed as a known exploit in the CISA KEV catalog. Based on the description, the likely attack vector is the execution of maliciously crafted image data through the fx operation, which could be triggered when processing untrusted images or input files. The CVE data does not specify the privilege level required to supply the crafted argument.
OpenCVE Enrichment
Github GHSA