"CISA Alerts on Active Exploits in Chrome and Excel Library Vulnerabilities"

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned of two actively exploited vulnerabilities: a heap buffer overflow in Google Chrome's WebRTC (CVE-2023-7024) and a remote code execution flaw in the Spreadsheet::ParseExcel Perl library (CVE-2023-7101). Federal agencies are required to address these issues by January 23. The Spreadsheet::ParseExcel vulnerability has been exploited by Chinese hackers, notably affecting Barracuda's Email Security Gateway. Google has already issued an emergency update to patch the Chrome vulnerability, marking the eighth zero-day fixed in the browser for the year. CISA's KEV catalog helps organizations prioritize vulnerability management.
Reading Insights
0
13
2 min
vs 3 min read
78%
417 → 93 words
Want the full story? Read the original article
Read on BleepingComputer