CVE-2021-22204: ExifTool Remote Code Execution Vulnerability
Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image Required action: Apply updates per vendor instructions.
· high severity · unattributed attribution
Evidence and provenance
- Original source
- CISA KEV report ↗
- Published
- 2021-11-17T00:00:00Z
- Confidence basis
- No actor match
- Record ID
b0e71a43cbf32cf2536c
Vulnerabilities
CVE-2021-22204
Use and citation
Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.