Impact
ImageMagick before 7.1.2-30 contains a time-of-check time-of-use flaw in its path-policy enforcement on Windows. The flaw lets an attacker arrange for a symbolic link to be swapped between the policy check and the actual file access. By doing so, the attacker can read files that are otherwise blocked by the policy, or write to policy-denied locations, effectively bypassing all read or write restrictions imposed by the program. This flaw corresponds to the CWE-367 Race Condition and CWE-59 Path Manipulation weaknesses.
Affected Systems
ImageMagick. All versions prior to 7.1.2-30 are affected. The vulnerability applies to installations running on Windows platforms.
Risk and Exploitability
The CVSS score of 1 indicates a low severity metric, yet the impact can be considerable in environments where ImageMagick processes files from untrusted sources. Based on the description, it is inferred that the exploit requires the attacker to influence the symbolic link that ImageMagick resolves, so the likely attack vector is local or remote privilege escalation where the attacker can supply a crafted image file containing a symlink. Since the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, there is presently no evidence of widespread exploitation; however, the race condition could be abused with sufficient local access. In any case, the possibility of reading or writing protected files warrants timely remediation.
OpenCVE Enrichment