peter bassill · operator
$ cve CVE-2021-22204 JSON

CVE-2021-22204 KEV EXPLOIT

6.8
MEDIUM · CVSS 3.1 · EPSS 100% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2021-12-01.

Description

Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image

Scoring

CVSS6.8 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
EPSS99.98% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-94
On CISA KEVyes — remediate by 2021-12-01
Public exploityes
Published2021-04-23
Last modified2026-06-17

CISA KEV

NameExifTool Remote Code Execution Vulnerability
Added2021-11-17
Due2021-12-01
Vendor / productPerl / Exiftool
Ransomware usenone reported

Affected (3)

VendorProduct
debiandebian linux
exiftool projectexiftool
fedoraprojectfedora

Public exploits

SourceTitleDate
exploit-dbExifTool 12.23 - Arbitrary Code Execution2022-05-11

References

→ the Explorer  ·  watch your stack  ·  NVD