In the LibreOffice 7-1 series in versions before 7.1.2, and in the 7-0 series in versions before 7.0.5, the denylist can be circumvented by manipulating the link so it doesn't match the denylist but results in ShellExecute attempting to launch an executable type.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|