CVE-2021-39212
ImageMagick vulnerability analysis and mitigation

Overview

ImageMagick, a software suite used for editing and manipulating digital images, was found to have a security vulnerability (CVE-2021-39212) where Postscript files could be read and written when specifically excluded by a module policy in policy.xml. This vulnerability was discovered and disclosed on September 13, 2021, affecting versions prior to ImageMagick 7.1.0-7 and 6.9.12-22 (GitHub Advisory).

Technical details

The vulnerability stems from incorrect rights handling in the module policy implementation. The issue involved the system using incorrect rights checking, where AllPolicyRights were being used instead of the more restrictive ReadPolicyRights|WritePolicyRights combination. The vulnerability has a CVSS v3.1 score of 4.4 (Low) with Local attack vector, Low attack complexity, Low privileges required, and No user interaction needed (Oracle Bulletin).

Impact

The vulnerability could allow unauthorized access to read and write Postscript files that were specifically meant to be restricted by the module policy configuration. This represents a security policy bypass that could potentially expose sensitive information or allow unauthorized file modifications (GitHub Advisory).

Mitigation and workarounds

The issue has been patched in ImageMagick versions 7.1.0-7 and 6.9.12-22. As a workaround, users are recommended to use the coder policy instead of the module policy, as this is both more common and not affected by this vulnerability. Various Linux distributions have also released patched versions, including Ubuntu and Debian (GitHub Advisory, Ubuntu Security).

Additional resources


SourceThis report was generated using AI

Related ImageMagick vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-57807CRITICAL9.8
  • C#C#
  • libMagick++-devel
NoYesSep 05, 2025
CVE-2025-57803HIGH8.8
  • C#C#
  • ImageMagick-doc
NoYesAug 26, 2025
CVE-2025-62171HIGH7.5
  • C#C#
  • ImageMagick-doc
NoYesOct 17, 2025
CVE-2025-62594MEDIUM5.5
  • C#C#
  • Magick.NET-Q8-OpenMP-arm64
NoYesOct 27, 2025
CVE-2025-65955MEDIUM4.9
  • C#C#
  • Magick.NET-Q8-arm64
NoYesDec 02, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management