CVE-2023-7101 is an arbitrary code execution (ACE) vulnerability in Spreadsheet::ParseExcel version 0.65, a Perl module used for parsing Excel files, affecting various Debian and Fedora distributions. The vulnerability arises from the module's evaluation of unvalidated Number format strings within Excel files, leading to code execution. With a CVSS score of 7.8 (HIGH) and an EPSS score indicating high exploitability, this flaw allows an attacker to achieve full compromise (confidentiality, integrity, availability) with low attack complexity, requiring user interaction (e.g., opening a malicious Excel file). This CVE is actively exploited in the wild, as confirmed by its presence in CISA's KEV catalog, and has garnered significant community discussion and media coverage, despite no public exploit code being readily available on platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.65CPE matchmatch criteria | cpe:2.3:a:jmcnamara:spreadsheet\:\:parseexcel:*:*:*:*:*:perl:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* | ||
39CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.