CVE-2021-22204

high-risk
Published 2021-04-23

Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image

Do I need to act?

!
92.9% chance of exploitation in next 30 days
EPSS score — higher than 7% of all CVEs
!
CISA KEV: actively exploited in the wild
On the Known Exploited Vulnerabilities catalog — federal agencies must patch
!
1 public exploit available
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
6
CVSS 6.8/10 Medium
LOCAL / LOW complexity

References (29)

and 9 more references
62
/ 100
high-risk
Severity 22/34 · High
Exploitability 27/34 · High
Exposure 13/34 · Low