CVE-2021-22204: Exiftool RCE II

Bookmarked!

This exercise covers how you can gain code execution when an application uses exiftool on user-controlled files

PRO Medium < 1 Hr. 82 Media Badge
Course

In this exercise, you will learn how to exploit a vulnerability in <code>exiftool</code> discovered by William Bowling. The vulnerability involves manipulating a DjVu file and embedding it into a JPEG file to achieve arbitrary code execution.

Skills covered
Injection
CWE-94,CWE-74

Ready to practice?

Get access to this lab and 600+ hands-on exercises with a PRO subscription.