Netskope Threat Labs

FILE-MULTIMEDIA ImageMagick Out-of-bounds write on the heap attempted

IPS-CFWIPS-SWG

1 SID: 170194

First seen
October 2025
Last seen
September 2026

Detects an image exploiting CVE-2025-57807, a heap out-of-bounds write in ImageMagick's blob handling that can allow code execution. The rule matches the crafted zero-length allocations that public exploits use to corrupt heap memory.