VORANT. Threat Intelligence Sign in Get the full feed

Barracuda ESG zero-day exploited in wild

critical vulnerability

A code-execution flaw in Barracuda Email Security Gateway, stemming from a vulnerability in the Spreadsheet::ParseExcel library, is being actively exploited.

Japan's IPA has issued an advisory regarding an arbitrary code execution vulnerability (CVE-2023-7102) affecting Barracuda Networks' Email Security Gateway Appliance (ESG). The vulnerability allows unauthenticated remote attackers to execute arbitrary code on affected systems. According to the vendor, active exploitation of this vulnerability has already been observed in the wild.

The root cause has been traced to a vulnerability (CVE-2023-7101) in the open-source Spreadsheet::ParseExcel library, which Barracuda ESG uses for parsing Excel files. The library maintainers have released version 0.66 to address CVE-2023-7101. IPA advises that organizations using products or services that incorporate Spreadsheet::ParseExcel should upgrade to the latest version.

For Barracuda ESG customers, security updates are automatically applied according to the vendor. Organizations should verify that their appliances have received the necessary patches and monitor for any signs of compromise given the confirmed in-the-wild exploitation.

Mentioned in this report

Vulnerabilities CVE-2023-7101KEVCVE-2023-7102weaponized

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2023/alert20231225.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free