CVE-2016-3715 is a critical arbitrary file deletion vulnerability affecting ImageMagick versions before 6.9.3-10 and 7.x before 7.0.1-1, impacting various products including Canonical, Oracle, and Red Hat. This vulnerability, rated Medium severity with a CVSS score of 5.5, allows remote attackers to delete arbitrary files through a crafted image, requiring user interaction. It is actively exploited in the wild, as indicated by its presence in the KEV catalog and a high FAUCET Risk Score of 100/100. While no Metasploit or Nuclei modules exist, public exploit code is available on ExploitDB, and the vulnerability has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:* | ||
6.7CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_eus:6.7:*:*:*:*:*:*:* | ||
7.2CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_eus:7.2:*:*:*:*:*:*:* | ||
7.3CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_eus:7.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.