CISA Warns of Exploited Vulnerabilities in Chrome and Excel Parsing Library
ID: adb9c8ee-0c50-559f-b5f9-aee00a147125
STIX ID: report--adb9c8ee-0c50-559f-b5f9-aee00a147125
Feed Name: HackRead
Threat Score
CISA added two critical vulnerabilities to its KEV list — a patched Google Chrome WebRTC heap-buffer-overflow (CVE-2023-7024) and a remote-code-execution flaw in the Perl module Spreadsheet::ParseExcel (CVE-2023-7101) — urging federal agencies to mitigate by January 23; the Perl RCE has documented use by threat actors (including observed Chinese actor activity via Barracuda appliances) and a patched module (0.66) is available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
