CyberRota Analysis
AI analysis pending.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Detected Signals
arbitrary code execution code execution
GitHub PoC Links
External Security References
Note: these links are listed for security research and verification purposes only.
CISA KEV Details
Status: This CVE is listed in CISA's Known Exploited Vulnerabilities catalog.
Ransomware use: Unknown
Added to KEV: 2021-11-17
Required action: Apply updates per vendor instructions.
CVE
CVE-2021-22204
Severity
MEDIUM
CVSS
6.8
EPSS
99.98%
Original NVD Description
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image