CISA ADDS CHROME AND PERL LIBRARY FLAWS TO ITS KNOWN EXPLOITED VULNERABILITIES CATALOG
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-7024 | Actively Exploited Heap Buffer Overflow in Google Chrome WebRTC (CVE-2023-7024) CVE-2023-7024 is a high-severity heap buffer overflow (CWE-787) in the WebRTC component of Google Chrome/Chromium. A remote attacker can trigger it by convincing a user to open a crafted HTML page (user interaction is required per the CVSS score), causing memory corruption in the browser. Successful exploitation can crash the browser or potentially allow arbitrary code execution, with high impact on confidentiality, integrity, and availability. Anyone running Google Chrome prior to 120.0.6099.129 is affected, as are users of Chromium builds packaged by Debian and Fedora. The flaw is being exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2024-01-02, and Google addressed it as an actively exploited zero-day — with an EPSS probability of ~7.4% of exploitation within 30 days (94th percentile). Do: Update Google Chrome to 120.0.6099.129 or later immediately (verify via chrome://settings/help, since many installs auto-update but require a relaunch); organizations on Debian or Fedora should apply their distribution's patched chromium security update. Per CISA KEV requirements, federal agencies must apply vendor mitigations or discontinue use of affected builds by the required deadline. Until patched, avoid opening untrusted web pages, as exploitation requires user interaction with crafted HTML content. | 8.8 | 7% | KEV PoC |
| mass≈3 billion+ users/installs (Chrome's global install base) | |
| CVE-2023-7101 | Arbitrary Code Execution in Spreadsheet::ParseExcel Perl Module (CVE-2023-7101) CVE-2023-7101 is an arbitrary code execution flaw in version 0.65 of the Spreadsheet::ParseExcel Perl module, which is used to parse Microsoft Excel files: Excel 'Number format' strings taken from the file are passed into Perl's string-form eval() without validation (CWE-95), so embedded content is evaluated as Perl code. It is triggered whenever an application, script, or appliance using the module processes a maliciously crafted .xls file, meaning exploitation typically requires user interaction (opening or ingesting the file) consistent with the CVSS local-attack/user-interaction vector. A successful attacker gains code execution with the privileges of the process parsing the file, with high impact on confidentiality, integrity, and availability. Anyone running the vulnerable module is affected, including Debian and Fedora users of its packages and operators of products that bundle the library, and the flaw drew wide attention after it was implicated in the Barracuda Email Security Gateway zero-day exploitation attributed to Chinese-nexus hackers. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2024-01-02, confirming exploitation in the wild; EPSS assigns a roughly 19% probability of exploitation in the next 30 days (97th percentile), and no public proof-of-concept is known. Do: Upgrade Spreadsheet::ParseExcel to the vendor-patched release (version 0.65 is cited as vulnerable) via CPAN or by applying updated Debian/Fedora packages, and identify products that bundle the module, such as Barracuda ESG, applying those vendors' fixes per their instructions. Until patched, avoid processing untrusted .xls files with the module or restrict spreadsheet ingestion to trusted sources, and review systems where Perl code parses externally supplied spreadsheets for signs of exploitation. Ransomware linkage is currently unknown, per CISA. | 7.8 | 19% | KEV |
| largetens of thousands to hundreds of thousands of systems (long-standing library shipped in Debian/Fedora package repositories and bundled in third-party products) | |
| CVE-2023-7102 | Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue affected Barracuda ESG Appliance, from 5.1.3.001 through 9.2.1.001, until Barracuda removed the vulnerable logic. NVD description · AI analysis pending | 9.8 | 45% |
| — |
Full article348 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chrome and Perl library flaws to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two Qlik Sense vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog.
Below is the list of the issues added to the catalog:
CVE-2023-7024 – The vulnerability is a Heap buffer overflow issue in WebRTC. The flaw was reported by Clément Lecigne and Vlad Stolyarov of Google’s Threat Analysis Group on 2023-12-19 and fixed in just one day. Google released emergency updates to address this zero-day vulnerability. The fact that the issue was discovered by Google TAG suggests it was exploited by a nation-state actor or by a surveillance firm.
CVE-2023-7101 – The flaw is Spreadsheet::ParseExcel Remote Code Execution Vulnerability. The issue stems from the evaluation of Number format strings within the Excel parsing logic.
On December 21, network and email cybersecurity firm Barracuda started releasing security updates to address a zero-day, tracked as CVE-2023-7102, in Email Security Gateway (ESG) appliances. The vulnerability has been actively exploited by the Chinese hacker group UNC4841 Chinese. The root cause of the problem is a weakness in the Spreadsheet::ParseExcel third-party library. This library is used by the Amavis virus scanner that runs on Barracuda ESG appliances. An attacker can trigger the vulnerability to execute arbitrary code on vulnerable ESG appliances through parameter injection.
Barracuda has also filed CVE-2023-7101 for a vulnerability in the open-source library which is used in several products of multiple organizations. At the time of this writing the issue has yet to be addressed.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix these vulnerabilities by January 23, 2024.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/156854/security/cisa-adds-chrome-perl-library-flaws-known-exploited-vulnerabilities-catalog.html