CVE-2023-7101

Arbitrary Code Execution (ACE) Vulnerability

Basic Information

CVE State
PUBLISHED
Reserved Date
December 24, 2023
Published Date
December 24, 2023
Last Updated
February 13, 2025
Vendor
Douglas Wilson
Product
Spreadsheet::ParseExcel
Description
Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic.

CVSS Scores

CVSS v3.1

7.8 - HIGH

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

SSVC Information

Exploitation
active
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (added 2024-01-02 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2024-01-02 00:00:00 UTC