Executive brief
ImageMagick is a popular software suite used for creating, editing, and converting images. A vulnerability in its .NET library could allow a local user to bypass security policies and access files they should not be able to see. This could lead to the unauthorized exposure of sensitive data stored on the system.
Technical details
A policy bypass vulnerability exists in ImageMagick's Magick.NET library due to an incomplete fix for a previous security issue. The flaw involves improper link resolution (CWE-59) and a time-of-check time-of-use (TOCTOU) race condition (CWE-367). A local attacker with low privileges can exploit these weaknesses to bypass authorization checks and access unintended resources. The vulnerability is triggered when the product attempts to access a file without properly preventing the filename from resolving to a symbolic link or shortcut. This issue is addressed in Magick.NET version 14.15.0.
Affected products
- ImageMagick Magick.NET-Q16-AnyCPU < 14.15.0
- ImageMagick Magick.NET-Q16-HDRI-AnyCPU < 14.15.0
- ImageMagick Magick.NET-Q16-HDRI-OpenMP-arm64 < 14.15.0
- ImageMagick Magick.NET-Q16-HDRI-arm64 < 14.15.0
- ImageMagick Magick.NET-Q16-HDRI-x64 < 14.15.0
- ImageMagick Magick.NET-Q16-HDRI-x86 < 14.15.0
- ImageMagick Magick.NET-Q16-OpenMP-arm64 < 14.15.0
- ImageMagick Magick.NET-Q16-OpenMP-x64 < 14.15.0
- ImageMagick Magick.NET-Q16-arm64 < 14.15.0
- ImageMagick Magick.NET-Q16-x64 < 14.15.0
- ImageMagick Magick.NET-Q16-x86 < 14.15.0
- ImageMagick Magick.NET-Q8-AnyCPU < 14.15.0
- ImageMagick Magick.NET-Q8-OpenMP-arm64 < 14.15.0
- ImageMagick,versions: Magick.NET-Q8-OpenMP-x64 < 14.15.0
- ImageMagick Magick.NET-Q8-arm64 < 14.15.0
- ImageMagick Magick.NET-Q8-x64 < 14.15.0
- ImageMagick Magick.NET-Q8-x86 < 14.15.0
Timeline
- 2026-06-26: patched: Magick.NET 14.15.0 released
- 2026-07-24: advisory: GitHub Advisory published