{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/imagemagick--7.1.2-33--6.9.13-58/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7,"id":"CVE-2026-108693"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ImageMagick (\u003c= 7.1.2-33, \u003c= 6.9.13-58)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","code-execution","windows"],"_cs_type":"advisory","_cs_vendors":["ImageMagick"],"content_html":"\u003cp\u003eImageMagick on Windows, specifically versions through 7.1.2-33 and 6.9.13-58, contains an uncontrolled search path vulnerability within the NTGhostscriptEXE() function. When the Ghostscript utility is not explicitly registered in the system environment, ImageMagick attempts to locate and execute the 'gswin64c.exe' binary using its bare name. This behavior allows the application to search the current working directory before system-wide paths. An attacker with the ability to influence the working directory of the ImageMagick process - often by inducing a user to convert a malicious PDF, PostScript, or EPS file - can plant a rogue executable named 'gswin64c.exe'. When ImageMagick is triggered to process the file, it will execute the attacker-supplied binary with the privileges of the ImageMagick process, leading to arbitrary code execution.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows local arbitrary code execution with the permissions of the user running the ImageMagick utility. This vulnerability impacts all Windows deployments of ImageMagick within the specified version ranges that have not registered Ghostscript globally. If exploited, an attacker could achieve persistence, exfiltrate local data, or pivot within the host environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching ImageMagick to a version beyond 7.1.2-33 or 6.9.13-58 as soon as an official fix is provided by the vendor. In the interim, ensure Ghostscript is correctly registered in the system environment variables to prevent the application from defaulting to insecure local path lookups for 'gswin64c.exe'.\u003c/p\u003e\n","date_modified":"2026-10-11T03:58:06Z","date_published":"2026-10-11T03:58:06Z","id":"https://feed.craftedsignal.io/briefs/2026-10-imagemagick-search-path/","summary":"ImageMagick versions through 7.1.2-33 and 6.9.13-58 are vulnerable to arbitrary code execution via binary planting due to an insecure search path for gswin64c.exe.","title":"Uncontrolled Search Path Vulnerability in ImageMagick on Windows","url":"https://feed.craftedsignal.io/briefs/2026-10-imagemagick-search-path/"}],"language":"en","title":"CraftedSignal Threat Feed - ImageMagick (\u003c= 7.1.2-33, \u003c= 6.9.13-58)","version":"https://jsonfeed.org/version/1.1"}