ZeroHour

CVE-2016-3714

KEVmass

Command Injection RCE in ImageMagick Image Coders (ImageTragick)

CISA: ImageMagick Improper Input Validation Vulnerability

CVSS 3.1
8.4 high
EPSS
97%p100
Published
()
KEV added
AI analysis

ImageTragick (CVE-2016-3714) is an improper input validation flaw in ImageMagick's EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, and PLT coders that allows shell metacharacters embedded in a crafted image to be passed to the command shell. It is triggered whenever ImageMagick processes a malicious image file — typically when a web application converts or thumbnails user-supplied uploads or URLs. A successful attacker gains arbitrary command and code execution on the host running ImageMagick, with the privileges of that process. Anyone running affected versions of ImageMagick — before 6.9.3-10 in the 6.x line or before 7.0.1-1 in the 7.x line, including builds shipped with Ubuntu, Debian, openSUSE/Leap and SUSE Linux Enterprise Server — is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-09, and EPSS places its 30-day exploitation probability at 97.5% (100th percentile), consistent with active exploitation.

What to do: Upgrade ImageMagick to 6.9.3-10 or later (6.x) or 7.0.1-1 or later (7.x), or apply the security updates issued by Ubuntu, Debian, openSUSE and SUSE. As an interim mitigation, disable or restrict the vulnerable coders (EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, PLT) via ImageMagick's policy.xml and avoid passing user-controlled filenames or URLs unfiltered to ImageMagick. Prioritize auditing internet-facing services that process user-uploaded images (CMSs, forums, image pipelines), which are the typical delivery path for this flaw.

Affected
ImageMagick (6.x line)before 6.9.3-10
ImageMagick (7.x line)7.x before 7.0.1-1
Canonical Ubuntu Linux
Debian Linux
openSUSE / openSUSE Leap
SUSE Linux Enterprise Server
Estimated exposure
massmillions of installations worldwide (ImageMagick ships by default with Ubuntu, Debian, openSUSE and SLES and underpins image processing on a very large share… — ImageMagick is a default or near-default component of the affected Linux distributions and is widely embedded in web upload, thumbnailing and image-conversion pipelines, so the realistic exposed population is in the millions of servers and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."

CISA Known Exploited Vulnerability
Affected
ImageMagick ImageMagick
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
imagemagickcanonicaldebianopensusesuse
Products
imagemagick, ubuntu linux, debian linux, leap, opensuse, suse linux enterprise server
Weakness
CWE-20
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news