EXPOSURES › CVE-2016-3715
CVE-2016-3715
HIGH ⌖ ON CISA KEV · EXPLOITEDImageMagick's ephemeral pseudo protocol allowed arbitrary file deletion, a known vulnerability (CVE-2016-3715) that remains actively exploited in the wild.
The ephemeral pseudo protocol in ImageMagick permitted users to delete files after reading them, a flaw that has persisted since 2016 and is now on CISA's KEV catalog. DIB organizations must ensure ImageMagick is patched to the latest version to prevent data loss and maintain compliance with NIST 800-171's requirement for timely patching of known vulnerabilities. Failure to patch exposes systems to data destruction and potential ransomware leverage, as attackers can use file deletion to disrupt operations or hide malicious payloads.
Shame score — A known vulnerability from 2016 that remained unpatched and is actively exploited in the wild, demonstrating severe negligence in patch management and supply chain security.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
ImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol, which deletes files after reading.
"ImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol, which deletes files after reading."