CISA added two vulnerabilities to the list of Known Exploitable Vulnerabilities: one that was recently patched in Google Chrome and a second that affects an open-source Perl library in Excel, called Spreadsheet::ParseExcel.

The US agency has given federal agencies until January 23 to patch the two vulnerabilities. The first vulnerability is tracked as CVE-2023-7024 and the second as CVE-2023-7101. Organizations are urged to patch the vulnerabilities based on vendor advice. Alternatively, they should stop using the vulnerable products.
See also: Ivanti patches critical vulnerabilities in Avalanche
Spreadsheet::ParseExcel: Vulnerability allows remote code execution
The first issue that CISA added to the list of vulnerabilities used in attacks is CVE-2023-7101, a vulnerability that allows remote code execution and affects versions 0.65 and earlier of the library Spreadsheet::ParseExcel
The issue stems from the evaluation of Number format strings within Excel parsing logic.
Spreadsheet::ParseExcel is a general-purpose library that enables data import/export and other operations on Excel files. The product also provides a compatibility layer for processing files in Perl-based web apps.
One product that uses this library is the Barracuda ESG (Email Security Gateway), which was targeted in late December by Chinese hackers who exploited the CVE-2023-7101 vulnerability in Spreadsheet::ParseExcel to compromise devices.
See also: Google: Fixes zero-day vulnerability in Chrome browser
Barracuda released security updates on December 29, 2023, to address the issue (Spreadsheet::ParseExcel version 0.66).
Google Chrome: Buffer overflow vulnerability
The vulnerability in Google Chrome is tracked as CVE-2023-7024 and is a heap buffer overflow issue in WebRTC in Google Chrome.
“Google Chromium WebRTC, an open-source project that provides browsers with real-time communication, contains a vulnerability that could allow an attacker to cause crashes or execute code,” CISA reports.

“This vulnerability could affect web browsers that use WebRTC, including but not limited to Google Chrome,” the service adds.
The flaw was discovered by Analysis Team Threat Google's and was patched on December 20, in versions 120.0.6099.129/130 for Windows and 120.0.6099.129 for Mac and Linux.
CISA's KEV list is very useful for organizations around the world who want to learn about new threats and are interested in better vulnerability management and prioritization.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Hackers exploit old MS Excel vulnerability to spread Agent Tesla malware
Overall, CISA helps a lot in protecting and addressing cybersecurity threats. This organization works with various sectors, such as private businesses, state governments, and local authorities, to improve the security of digital systems.
It provides information and tools to help organizations protect their networks from cyberattacks and deal with any attacks that may occur.
In addition, it informs the public about any vulnerabilities in systems and applications.
Overall, CISA's role is vital to protecting the digital infrastructure of the US and other regions.
Source: www.bleepingcomputer.com
