VulnerabilityAnalyzed
CVE-2021-22204
ExifTool Remote Code Execution Vulnerability
KEVHIGH 7.8EPSS 100.0%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 1 December 2021). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 99.98% probability · 100th percentile
- CISA KEV
- Listed 17 November 2021 · due 1 December 2021
- Weakness
- CWE-94
- Affected
- exiftool project/exiftool · debian/debian linux · fedoraproject/fedora
- Source
- cve@gitlab.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2021-22204
References
- http://packetstormsecurity.com/files/162558/ExifTool-DjVu-ANT-Perl-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/164768/GitLab-Unauthenticated-Remote-ExifTool-Command-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/164994/GitLab-13.10.2-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/167038/ExifTool-12.23-Arbitrary-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2021/05/09/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/05/10/5Mailing List, Third Party Advisory
- https://github.com/exiftool/exiftool/commit/cf0f4e7dcd024ca99615bfd1102a841a25dde031#diff-fa0d652d10dbcd246e6b1df16c1e992931d3bb717a7e36157596b76bdadb3800Patch
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22204.jsonThird Party Advisory
- https://hackerone.com/reports/1154542Exploit, Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/05/msg00018.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DDKDLJLBTBBR66OOPXSXCG2PQRM5KCZL/Release Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F6UOBPU3LSHAPRRJNISNVXZ5DSUIALLV/Release Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U4RF6PJCJ6NQOVJJJF6HN6BORUQVIXY6/Release Notes
- https://www.debian.org/security/2021/dsa-4910Mailing List, Third Party Advisory
- http://packetstormsecurity.com/files/162558/ExifTool-DjVu-ANT-Perl-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/164768/GitLab-Unauthenticated-Remote-ExifTool-Command-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/164994/GitLab-13.10.2-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/167038/ExifTool-12.23-Arbitrary-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2021/05/09/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/05/10/5Mailing List, Third Party Advisory
- https://github.com/exiftool/exiftool/commit/cf0f4e7dcd024ca99615bfd1102a841a25dde031#diff-fa0d652d10dbcd246e6b1df16c1e992931d3bb717a7e36157596b76bdadb3800Patch
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22204.jsonThird Party Advisory
- https://hackerone.com/reports/1154542Exploit, Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/05/msg00018.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DDKDLJLBTBBR66OOPXSXCG2PQRM5KCZL/Release Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F6UOBPU3LSHAPRRJNISNVXZ5DSUIALLV/Release Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U4RF6PJCJ6NQOVJJJF6HN6BORUQVIXY6/Release Notes
- https://www.debian.org/security/2021/dsa-4910Mailing List, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22204US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.