EXPOSURES › CVE-2021-22204
CVE-2021-22204
HIGH ⌖ ON CISA KEV · EXPLOITEDExifTool versions 7.44+ allows remote code execution via malicious DjVu files due to improper neutralization of user data.
ExifTool, a widely used metadata extraction tool, suffered a remote code execution vulnerability when parsing DjVu files. DIB organizations must care because this flaw was actively exploited in the wild (KEV), enabling attackers to execute arbitrary code on systems processing such files. The failure stems from a known, unpatched vulnerability that was not responsibly disclosed or patched before exploitation, representing a severe compliance and operational risk.
Shame score — A known, unpatched RCE vulnerability in a widely deployed tool was actively exploited in the wild, indicating severe negligence in patch management and vulnerability disclosure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image