ZeroHour

CVE-2021-22204

KEV PoC ×5mass

Eval Injection in ExifTool DjVu Parsing Enables Remote Code Execution

CISA: ExifTool Remote Code Execution Vulnerability

CVSS 3.1
7.8 high
EPSS
100%p100
Published
()
KEV added
AI analysis

CVE-2021-22204 is a code-injection flaw (CWE-95) in ExifTool, a widely used Perl library for reading and writing file metadata: versions 7.44 and later improperly neutralize user-supplied data when parsing the DjVu file format. It is triggered when ExifTool processes a crafted image or DjVu file, causing attacker-controlled input to be evaluated and executed in the context of the process doing the parsing. An attacker who can get a malicious file parsed, for example through a web service, media pipeline, or desktop application that extracts metadata from uploaded files, gains arbitrary code execution on the host. Any deployment running an affected ExifTool version that handles untrusted files is exposed, and because ExifTool is embedded inside many third-party products, affected systems may not have ExifTool visible in their inventory by name. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-17, EPSS assigns it a 100% probability of exploitation within 30 days (top percentile), and CISA's required action is to apply updates per vendor instructions.

What to do: Upgrade ExifTool to version 12.38 or later wherever it is installed directly or bundled inside other software, and apply vendor-supplied patches for any third-party products that embed ExifTool. Prioritize systems that parse untrusted or user-uploaded images; as an interim mitigation, block or strip DjVu-formatted uploads and disable DjVu metadata extraction until patching is complete. Because the flaw is in CISA's KEV catalog with an active exploitation window, treat remediation as urgent and verify asset inventory for embedded copies of ExifTool.

Affected
Perl ExifTool7.44 and later (all releases up to the fixed version; fixed in the vendor's 12.38 release)
Estimated exposure
massplausibly millions of installations worldwide; internet-exposed count unknown — ExifTool is a ubiquitous open-source metadata-parsing library bundled in thousands of applications, web upload pipelines, and imaging products, and every release from 7.44 onward (a span of well over a decade) is affected, making a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image

CISA Known Exploited Vulnerability
Affected
Perl Exiftool
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
exiftool projectdebianfedoraproject
Products
exiftool, debian linux, fedora
Weakness
CWE-94
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news