CVE-2023-34152

CRITICAL

ImageMagick - RCE

Title source: llm

Description

A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.

Exploits (2)

nomisec WORKING POC 10 stars
by overgrowncarrot1 · poc
https://github.com/overgrowncarrot1/ImageTragick_CVE-2023-34152
nomisec WORKING POC 3 stars
by SudoIndividual · poc
https://github.com/SudoIndividual/CVE-2023-34152

Scores

CVSS v3 9.8
EPSS 0.7496
EPSS Percentile 98.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78 CWE-20
Status published
Products (6)
fedoraproject/extra_packages_for_enterprise_linux 8.0
fedoraproject/fedora 37
fedoraproject/fedora 38
imagemagick/imagemagick < 7.1.1-11
redhat/enterprise_linux 6.0
redhat/enterprise_linux 7.0
Published May 30, 2023
Tracked Since Feb 18, 2026