KEVIntel
6.8
CVSS
Medium

CVE-2021-22204

PUBLISHED

Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the...

Exploited in the wild Low complexity No user interaction
Vendor
ExifTool
Product
ExifTool
Published
Apr 23, 2021
EPSS

Description

Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image

cisa metasploit

CVSS scores

CVSS v3.1 6.8 Medium

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

Exploitation status

Exploited in the wild

Recorded 2021-11-17 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
partial

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Nov 17, 2021
CISA Nov 17, 2021

Scanner integrations

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

gitlab_exif_rce

metasploit · Created Unknown

Metasploit module for CVE-2021-22204

Akash7350/CVE-2021-22204

github · Created 2023-05-14 03:43:28 UTC · 4 stars

UNICORDev/exploit-CVE-2021-22204

github · Created 2022-04-16 22:49:47 UTC · 41 stars

Exploit for CVE-2021-22204 (ExifTool) - Arbitrary Code Execution

mr-tuhin/CVE-2021-22204-exiftool

github · Created 2022-02-21 11:07:19 UTC · 8 stars

exiftool exploit

0xBruno/CVE-2021-22204

github · Created 2022-01-30 03:11:56 UTC · 2 stars

A complete PoC for CVE-2021-22204 exiftool RCE

trganda/CVE-2021-22204

github · Created 2021-12-29 13:41:35 UTC · 3 stars

ph-arm/CVE-2021-22204-Gitlab

github · Created 2021-11-04 14:31:02 UTC · 2 stars

Modification of gitlab exploit anything under 13.10

AssassinUKG/CVE-2021-22204

github · Created 2021-08-02 18:56:16 UTC · 27 stars

PenTestical/CVE-2021-22204

github · Created 2021-08-02 09:11:27 UTC · 3 stars

bilkoh/POC-CVE-2021-22204

github · Created 2021-05-21 00:14:52 UTC · 8 stars

POC for exiftool vuln (CVE-2021-22204).

se162xg/CVE-2021-22204

github · Created 2021-05-12 08:51:44 UTC · 11 stars

exiftool arbitrary code execution vulnerability

convisolabs/CVE-2021-22204-exiftool

github · Created 2021-05-11 18:45:07 UTC · 93 stars

Python exploit for the CVE-2021-22204 vulnerability in Exiftool

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Added to KEVIntel

  • Detected by Metasploit