November 17, 2021 · Applied Cybernetics Group
CVE-2021-22204 — Perl Exiftool
ExifTool Remote Code Execution Vulnerability
- Added to KEV
2021-11-17- Federal due date
2021-12-01- Vendor
- Perl
- Product
- Exiftool
- EPSS
- 99.8th percentile (score 0.928, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2021-22204
CISA short description
Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
Required action
Apply updates per vendor instructions.