CVE-2016-3714: ImageTragick
A remote code execution vulnerability in ImageMagick caused by insufficient filtering of shell metacharacters in filenames passed to its delegate commands. An application that merely processes a user-supplied image, such as generating a thumbnail, can be compromised by a crafted file that abuses coders like MVG or URL to run arbitrary shell commands.
View the authoritative record on NVD ↗Affected software
- ImageMagick before 6.9.3-10
How it's exploited
Submit a crafted image file, often disguised with a valid image magic byte header, containing an embedded filename or URL with shell metacharacters that a vulnerable delegate coder (such as MVG, MSL, EPHEMERAL, or HTTPS) passes unsanitized to a shell command, achieving arbitrary command execution the moment the file is processed.
Severity
CVE-2016-3714 carries a CVSS 3.1 base score of 8.4, rated High. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2016-3714 is categorized under CWE-20, the general weakness pattern behind this specific vulnerability.
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Remediation
Upgrade to ImageMagick 6.9.3-10 or later, and as defense-in-depth regardless of version, disable the vulnerable coders (MVG, MSL, EPHEMERAL, URL, HTTPS, SHOW, WIN, PLT) in policy.xml.
Frequently asked questions
What is CVE-2016-3714?
A remote code execution vulnerability in ImageMagick caused by insufficient filtering of shell metacharacters in filenames passed to its delegate commands. An application that merely processes a user-supplied image, such as generating a thumbnail, can be compromised by a crafted file that abuses coders like MVG or URL to run arbitrary shell commands.
How severe is CVE-2016-3714?
CVE-2016-3714 has a CVSS 3.1 base score of 8.4 out of 10, rated High.
What software is affected by CVE-2016-3714?
CVE-2016-3714 affects ImageMagick before 6.9.3-10.
How do you fix CVE-2016-3714?
Upgrade to ImageMagick 6.9.3-10 or later, and as defense-in-depth regardless of version, disable the vulnerable coders (MVG, MSL, EPHEMERAL, URL, HTTPS, SHOW, WIN, PLT) in policy.xml.
Where is the authoritative record for CVE-2016-3714?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2016-3714 at https://nvd.nist.gov/vuln/detail/CVE-2016-3714, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest