CVE-2021-22204
KEV PoC ×5massEval Injection in ExifTool DjVu Parsing Enables Remote Code Execution
CISA: ExifTool Remote Code Execution Vulnerability
CVE-2021-22204 is a code-injection flaw (CWE-95) in ExifTool, a widely used Perl library for reading and writing file metadata: versions 7.44 and later improperly neutralize user-supplied data when parsing the DjVu file format. It is triggered when ExifTool processes a crafted image or DjVu file, causing attacker-controlled input to be evaluated and executed in the context of the process doing the parsing. An attacker who can get a malicious file parsed, for example through a web service, media pipeline, or desktop application that extracts metadata from uploaded files, gains arbitrary code execution on the host. Any deployment running an affected ExifTool version that handles untrusted files is exposed, and because ExifTool is embedded inside many third-party products, affected systems may not have ExifTool visible in their inventory by name. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-17, EPSS assigns it a 100% probability of exploitation within 30 days (top percentile), and CISA's required action is to apply updates per vendor instructions.
What to do: Upgrade ExifTool to version 12.38 or later wherever it is installed directly or bundled inside other software, and apply vendor-supplied patches for any third-party products that embed ExifTool. Prioritize systems that parse untrusted or user-uploaded images; as an interim mitigation, block or strip DjVu-formatted uploads and disable DjVu metadata extraction until patching is complete. Because the flaw is in CISA's KEV catalog with an active exploitation window, treat remediation as urgent and verify asset inventory for embedded copies of ExifTool.
| Perl ExifTool | 7.44 and later (all releases up to the fixed version; fixed in the vendor's 12.38 release) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
- Affected
- Perl Exiftool
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- exiftool projectdebianfedoraproject
- Products
- exiftool, debian linux, fedora
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H