Skip to content
COOEY

EXPOSURES › CVE-2016-3715

CVE-2016-3715

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2016-3715 ↗
⌖ EXPLOITED IN THE WILD SHAME 85/100 exploited-in-wildunpatched

ImageMagick's ephemeral pseudo protocol allowed arbitrary file deletion, a known vulnerability (CVE-2016-3715) that remains actively exploited in the wild.

The ephemeral pseudo protocol in ImageMagick permitted users to delete files after reading them, a flaw that has persisted since 2016 and is now on CISA's KEV catalog. DIB organizations must ensure ImageMagick is patched to the latest version to prevent data loss and maintain compliance with NIST 800-171's requirement for timely patching of known vulnerabilities. Failure to patch exposes systems to data destruction and potential ransomware leverage, as attackers can use file deletion to disrupt operations or hide malicious payloads.

Shame score — A known vulnerability from 2016 that remained unpatched and is actively exploited in the wild, demonstrating severe negligence in patch management and supply chain security.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

ImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol, which deletes files after reading.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
Critical vulnerability allowing arbitrary file deletion via ephemeral protocol
cooey ↗ severe-fallout -0.80
Critical vulnerability allowing arbitrary file deletion via ephemeral protocol
"ImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol, which deletes files after reading."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.