SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2021-22204

ExifTool Remote Code Execution Vulnerability

KEVHIGH 7.8EPSS 100.0%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 1 December 2021). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
99.98% probability · 100th percentile
CISA KEV
Listed 17 November 2021 · due 1 December 2021
Weakness
CWE-94
Affected
exiftool project/exiftool · debian/debian linux · fedoraproject/fedora
Source
cve@gitlab.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2021-22204

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.