Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 97.5%; technical severity is CVSS 8.4.
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."
Who should care
- Teams operating Ubuntu Linux, Debian Linux, Imagemagick +3 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Ubuntu Linux, Debian Linux, Imagemagick +3 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Debian Security advisory Dsa 3580
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Advisory
- Debian Security advisory Dsa 3580Debian · Vendor sourceVerification pending ↗
- Debian Security advisory Dsa 3746Debian · Vendor sourceVerification pending ↗
- Oracle Security advisory Bulletinjul2016 3090568Oracle · Vendor sourceVerification pending ↗
- Oracle Security advisory Linuxbulletinapr2016 2952096Oracle · Vendor sourceVerification pending ↗
- Red Hat Security advisory 2296071Red Hat · Vendor sourceVerification pending ↗
- Red Hat Security advisory Show Bug.cgiRed Hat · Vendor sourceVerification pending ↗
Technical details
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-20
- Affected versions
- Canonical Ubuntu Linux (Version 12.04 | Version 14.04 | Version 15.10 | Version 16.04); Debian Debian Linux (Version 8.0 | Version 9.0); Imagemagick Imagemagick (End Including 6.9.3-9 | Version 7.0.0-0 | Version 7.0.1-0); Opensuse Leap (Version 42.1); Opensuse Opensuse (Version 13.2); Suse Suse Linux Enterprise Server (Version 12)
- Fixed versions
- No explicit fixed version is currently recorded.
- Published
- 5 May 2016
- Attack vector
- Local
- Privileges required
- None
- User interaction
- None
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 97.5%
- Signal calculated at 83
External references
- Red Hat Third-party advisory RHSA 2016 0726
- Ubuntu Third-party advisory USN-2990-1
- CERT/CC Government advisory 250519
- CISA Government advisory CVE-2016-3714
- Lists Opensuse Third-party advisory Msg00024
- Lists Opensuse Third-party advisory Msg00025
- Lists Opensuse Third-party advisory Msg00028
- Lists Opensuse Third-party advisory Msg00032
- Lists Opensuse Third-party advisory Msg00041
- Lists Opensuse Third-party advisory Msg00051
- Packetstormsecurity Exploit information ImageTragick ImageMagick Proof Of Concepts
- Openwall Technical reference