CVE-2021-22204 is a critical arbitrary code execution vulnerability affecting ExifTool versions 7.44 and higher, stemming from improper neutralization of user data in DjVu files. This flaw allows attackers to execute arbitrary code when a malicious image is parsed. With a CVSS score of 7.8 (HIGH), it presents a significant risk due to its low attack complexity and potential for complete compromise of confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, with multiple public exploit modules available in Metasploit and ExploitDB, and has garnered substantial community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.44, < 12.24CPE matchmatch criteria | cpe:2.3:a:exiftool_project:exiftool:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.