Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-86422

Опубликовано: 07 сент. 2026
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink race conditions. Attackers can swap symlinks between policy validation and file access to read or write policy-denied files.

A flaw was found in ImageMagick. This vulnerability, known as a time-of-check-time-of-use (TOCTOU) flaw, affects path policy enforcement on Windows. A local attacker can exploit this by manipulating symbolic links (symlinks) during the brief interval between when the system checks a file's permissions and when it actually accesses the file. This allows the attacker to bypass security restrictions and potentially read or write files that should be protected by policy, leading to unauthorized information disclosure or data modification.

Отчет

Red Hat has evaluated this issue and determined that Red Hat products are not affected. This vulnerability only applies to Windows platforms.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickNot affected
Red Hat Enterprise Linux 7ImageMagickNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-367
https://bugzilla.redhat.com/show_bug.cgi?id=2529438ImageMagick: ImageMagick: Information disclosure and modification via TOCTOU symlink race on Windows

EPSS

Процентиль: 1%
0.00103
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
7 дней назад

(ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulne ...)

CVSS3: 3.3
nvd
9 дней назад

ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink race conditions. Attackers can swap symlinks between policy validation and file access to read or write policy-denied files.

CVSS3: 3.3
debian
9 дней назад

ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulne ...

CVSS3: 3.3
github
9 дней назад

ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink race conditions. Attackers can swap symlinks between policy validation and file access to read or write policy-denied files.

EPSS

Процентиль: 1%
0.00103
Низкий

3.3 Low

CVSS3