Skip to content
COOEY

EXPOSURES › CVE-2016-3714

CVE-2016-3714

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-09-09 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2016-3714 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

ImageMagick's CVE-2016-3714 allows remote attackers to execute arbitrary code via shell metacharacters in crafted images.

This 2016 vulnerability remains unpatched in many ImageMagick installations, enabling remote code execution through image processing tools. DIB organizations must audit their ImageMagick usage and apply patches immediately to prevent exploitation via crafted image files.

Shame score — A known RCE vulnerability from 2016 remains widely unpatched in critical image processing libraries used by defense contractors.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

ImageMagick contains an improper input validation vulnerability that affects the EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, and PLT coders. This allows a remote attacker to execute arbitrary code via shell metacharacters in a crafted image.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.