CISA Adds Newly Exploited Excel, Chrome Flaws to Vulnerability Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, which must be patched by January 23rd. The vulnerabilities include:
- CVE-2023-7101: a remote code execution vulnerability in the Spreadsheet::ParseExcel library (versions 0.65 and older)
- CVE-2023-7024: a heap buffer overflow vulnerability in Google Chrome's WebRTC (versions 120.0.6099.129/130 for Windows and 120.0.6099.129 for Mac and Linux)