CVE-2024-41817
HIGH 7.8EPSS 0.9%
ImageMagick is a free and open-source software suite, used for editing and manipulating digital images. The `AppImage` version `ImageMagick` might use an empty path when setting `MAGICK_CONFIGURE_PATH` and `LD_LIBRARY_PATH` environment variables while executing, which might lead to arbitrary code execution by loading malicious configuration files or shared libraries in the current working directory while executing `ImageMagick`. The vulnerability is fixed in 7.11-36.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.0 HIGH
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 0.93% chance of exploitation in the next 30 days, 58th percentile
- Published
- 2024-07-29
- Updated
- 2024-08-02
Proof-of-concept exploits (3)
- ImageMagick/ImageMagick/security/advisories/GHSA-8rxc-922v-phg8
- Dxsk/CVE-2024-41817-poc4★ · 2025-03-19
- maikneysm/AutoPwn-Titanic.htb0★ · 2025-06-21