NA

CVE-2023-6186

Published: 11/12/2023 Updated: 31/12/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Insufficient macro permission validation of The Document Foundation LibreOffice allows an malicious user to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libreoffice libreoffice

fedoraproject fedora 38

debian debian linux 11.0

debian debian linux 12.0

Vendor Advisories

Reginaldo Silva discovered two security vulnerabilities in LibreOffice, which could result in the execution of arbitrary scripts or Gstreamer plugins when opening a malformed file For the oldstable distribution (bullseye), these problems have been fixed in version 1:704-4+deb11u8 For the stable distribution (bookworm), these problems have been ...
Description<!---->An insufficient permission validation vulnerability was found in LibreOffice In versions that support running commands in hyperlinks, an attacker can execute built-in macros without warning the userAn insufficient permission validation vulnerability was found in LibreOffice In versions that support running commands in hyperlink ...