CISA warns of actively exploited bugs in Chrome and Excel parsing library
ID: e121db15-cb7a-58d1-9fb4-05cf73b3a676
STIX ID: report--e121db15-cb7a-58d1-9fb4-05cf73b3a676
Feed Name: Bleeping Computer
Threat Score
CISA added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2023-7101, an RCE in the Perl Spreadsheet::ParseExcel library exploited in the wild (used against Barracuda ESG appliances by UNC4841 to deploy SeaSpy and Saltwater), and CVE-2023-7024, a Chrome WebRTC heap overflow zero-day fixed via emergency updates; vendors have provided patches and CISA issued mitigation guidance and deadlines.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
