LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings

Summary

Security researchers have demonstrated a proof-of-concept attack allowing malicious spreadsheets to execute arbitrary code in LibreOffice and Apache OpenOffice without triggering macro warnings. This exploit requires the programs' Java support to be enabled.

IFF Assessment

FOE

This vulnerability allows attackers to execute arbitrary code, posing a direct threat to users and their data.

Severity

7.8 High (AI Estimated)

The attack vector is local (user interaction required to open the malicious file), but it allows for arbitrary code execution, which has a significant impact on confidentiality, integrity, and availability. The exploitability is moderate due to the dependency on Java support being enabled.

Defender Context

This vulnerability highlights a critical blind spot in how office suites handle embedded code execution, especially when Java support is enabled. Defenders should ensure that users are aware of the risks associated with opening untrusted spreadsheets and consider disabling Java support in these applications if not strictly necessary.

Read Full Story →