Description
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."
In plain language
AI Act nowIf you use ImageMagick on your systems and you’re on a vulnerable version, attackers may be able to run commands from specially crafted images—this is a real, active risk and you should act.
CVE-2016-3714 is a remote code execution flaw (“ImageTragick”) in ImageMagick’s coders (EPHEMERAL/HTTPS/MVG/MSL/TEXT/SHOW/WIN/PLT) that allows crafted image content to inject shell metacharacters and execute arbitrary code; it is listed in CISA KEV with confirmed real-world exploitation.
What to do now
- Check your installed ImageMagick version on every server/workstation that processes images (for example, run
convert -versionor the OS package version command). - If your version is ImageMagick before 6.9.3-10, or ImageMagick 7.x before 7.0.1-1, plan an upgrade immediately.
- Upgrade ImageMagick to the first fixed version: 6.9.3-10 or later (for the 6.x line), and 7.0.1-1 or later (for the 7.x line).
- If you cannot upgrade right away, temporarily stop using ImageMagick for untrusted images and follow vendor mitigation guidance from ImageMagick (including the ImageTragick guidance) until you can patch.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2016-3714 and every CVE in our database. Create a free account — no credit card required.
Create Free Account