Junglewise Threat Intelligence

CVE-2021-22204: ExifTool Remote Code Execution Vulnerability

CVE-2021-22204 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-17

Executive brief

ExifTool fails to properly neutralize user data within the DjVu file format, leading to arbitrary code execution. An attacker can exploit this by providing a specially crafted malicious image for parsing.

Affected products

  • ExifTool ExifTool 7.44 and up

Timeline

  • 2021-04-13: patched: GitHub commit cf0f4e7dcd024ca99615bfd1102a841a25dde031 fixes the issue.
  • 2021-11-17: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2021-11-17: disclosed