« Volver al listado

CVE-2023-7101

Estado: AnalizadaAlta (7.8)⚠ Explotación activa

Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CISA KEV — explotada activamente

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

CWE-95/94 (eval injection) permite ejecución de código arbitrario en Perl al parsear Excel malicioso. AV:L/UI:R indica explotación local con interacción del usuario abriendo archivo.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-7101",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-7101",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "active"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-08-20T03:56:14.026771Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "mandiant-cve@google.com",
      "affectedData": [
        {
          "repo": "https://metacpan.org/release/DOUGW/Spreadsheet-ParseExcel-0.65/source/lib/Spreadsheet",
          "vendor": "Douglas Wilson",
          "product": "Spreadsheet::ParseExcel",
          "versions": [
            {
              "status": "affected",
              "version": "0.65"
            }
          ],
          "packageName": "Spreadsheet::ParseExcel",
          "collectionURL": "https://metacpan.org/pod/Spreadsheet::ParseExcel",
          "defaultStatus": "affected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:jmcnamara:spreadsheet\\:\\:parseexcel:0.41:*:*:*:*:perl:*:*"
          ],
          "vendor": "jmcnamara",
          "product": "spreadsheet\\",
          "versions": [
            {
              "status": "affected",
              "version": "0.41",
              "versionType": "custom",
              "lessThanOrEqual": "0.65"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:debian:debian_linux:10:*:*:*:*:*:*:*"
          ],
          "vendor": "debian",
          "product": "debian_linux",
          "versions": [
            {
              "status": "affected",
              "version": "10"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*",
            "cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*"
          ],
          "vendor": "fedoraproject",
          "product": "fedora",
          "versions": [
            {
              "status": "affected",
              "version": "38"
            },
            {
              "status": "affected",
              "version": "39"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*",
            "cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*"
          ],
          "vendor": "fedoraproject",
          "product": "fedora",
          "versions": [
            {
              "status": "affected",
              "version": "38"
            },
            {
              "status": "affected",
              "version": "39"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2023-12-24T22:15:07.983",
  "references": [
    {
      "url": "http://www.openwall.com/lists/oss-security/2023/12/29/4",
      "tags": [
        "Mailing List",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "mandiant-cve@google.com"
    },
    {
      "url": "https://github.com/jmcnamara/spreadsheet-parseexcel/blob/c7298592e102a375d43150cd002feed806557c15/lib/Spreadsheet/ParseExcel/Utility.pm#L171",
      "tags": [
        "Product"
      ],
      "source": "mandiant-cve@google.com"
    },
    {
      "url": "https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2023/MNDT-2023-0019.md",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "mandiant-cve@google.com"
    },
    {
      "url": "https://https://github.com/haile01/perl_spreadsheet_excel_rce_poc",
      "tags": [
        "Broken Link",
        "Third Party Advisory"
      ],
      "source": "mandiant-cve@google.com"
    },
    {
      "url": "https://https://github.com/jmcnamara/spreadsheet-parseexcel/commit/bd3159277e745468e2c553417b35d5d7dc7405bc",
      "tags": [
        "Broken Link",
        "Patch"
      ],
      "source": "mandiant-cve@google.com"
    },
    {
      "url": "https://https://metacpan.org/dist/Spreadsheet-ParseExcel",
      "tags": [
        "Broken Link",
        "Product"
      ],
      "source": "mandiant-cve@google.com"
    },
    {
      "url": "https://https://www.cve.org/CVERecord?id=CVE-2023-7101",
      "tags": [
        "Broken Link",
        "Third Party Advisory"
      ],
      "source": "mandiant-cve@google.com"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2023/12/msg00025.html",
      "tags": [
        "Mailing List"
      ],
      "source": "mandiant-cve@google.com"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IFEHKULQRVXHIV7XXK2RGD4VQN6Y4CV5/",
      "tags": [
        "Broken Link",
        "Mailing List"
      ],
      "source": "mandiant-cve@google.com"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M2FIWDHRYTAAQLGM6AFOZVM7AFZ4H2ZR/",
      "tags": [
        "Broken Link",
        "Mailing List"
      ],
      "source": "mandiant-cve@google.com"
    },
    {
      "url": "https://security.metacpan.org/2024/02/10/vulnerable-spreadsheet-parsing-modules.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "mandiant-cve@google.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2023/12/29/4",
      "tags": [
        "Mailing List",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/jmcnamara/spreadsheet-parseexcel/blob/c7298592e102a375d43150cd002feed806557c15/lib/Spreadsheet/ParseExcel/Utility.pm#L171",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2023/MNDT-2023-0019.md",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://https://github.com/haile01/perl_spreadsheet_excel_rce_poc",
      "tags": [
        "Broken Link",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://https://github.com/jmcnamara/spreadsheet-parseexcel/commit/bd3159277e745468e2c553417b35d5d7dc7405bc",
      "tags": [
        "Broken Link",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://https://metacpan.org/dist/Spreadsheet-ParseExcel",
      "tags": [
        "Broken Link",
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://https://www.cve.org/CVERecord?id=CVE-2023-7101",
      "tags": [
        "Broken Link",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2023/12/msg00025.html",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IFEHKULQRVXHIV7XXK2RGD4VQN6Y4CV5/",
      "tags": [
        "Broken Link",
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M2FIWDHRYTAAQLGM6AFOZVM7AFZ4H2ZR/",
      "tags": [
        "Broken Link",
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.metacpan.org/2024/02/10/vulnerable-spreadsheet-parsing-modules.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-7101",
      "tags": [
        "US Government Resource"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "mandiant-cve@google.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-95"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic."
    },
    {
      "lang": "es",
      "value": "Spreadsheet::ParseExcel version 0.65 es un módulo Perl utilizado para analizar archivos Excel. Spreadsheet::ParseExcel es afectado por una vulnerabilidad de ejecución de código arbitrario (ACE) debido a que se pasa una entrada no validada de un archivo a una \"evaluación\" de tipo cadena. Específicamente, el problema surge de la evaluación de cadenas de formato numérico (que no deben confundirse con cadenas de formato de estilo printf) dentro de la lógica de análisis de Excel."
    }
  ],
  "lastModified": "2026-06-17T06:52:04.040",
  "cisaActionDue": "2024-01-23",
  "cisaExploitAdd": "2024-01-02",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:jmcnamara:spreadsheet\\:\\:parseexcel:*:*:*:*:*:perl:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1C81AC37-3219-4A80-A89E-8BDC1E238F82",
              "versionEndIncluding": "0.65"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "07B237A9-69A3-4A9C-9DA0-4E06BD37AE73"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CC559B26-5DFC-4B7A-A27C-B77DE755DFF9"
            },
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B8EDB836-4E6A-4B71-B9B2-AA3E03E0F646"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "mandiant-cve@google.com",
  "cisaRequiredAction": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
  "cisaVulnerabilityName": "Spreadsheet::ParseExcel Remote Code Execution Vulnerability"
}