CVE-2021-25631: falha em The Document Foundation LibreOffice
denylist of executable filename extensions possible to bypass under windows
Publicada em · Atualizada em
3Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackepss 5.0%
probabilidade de exploração
5.0%top 8% das CVEs
exploração observada
nãonenhuma fonte reporta
In the LibreOffice 7-1 series in versions prior to 7.1.2, and in the 7-0 series in versions prior to 7.0.5, the denylist can be circumvented by manipulating the link so it doesn't match the denylist but results in ShellExecute attempting to launch an executable type.
Produtos afetados
The Document Foundation · LibreOfficeCVEs relacionadas — The Document Foundation LibreOffice
No mesmo produto, das mais perigosas para as menos.
CVE-2022-3140—Macro URL arbitrary script executionEPSS 5.7%CVE-2023-2255—Remote documents loaded without prompt via IFrameEPSS 2.2%CVE-2020-12802—remote graphics contained in docx format retrieved in 'stealth mode'EPSS 1.9%CVE-2020-12803—XForms submissions could overwrite local filesEPSS 1.7%CVE-2022-26307—Weak Master KeysEPSS 1.4%CVE-2020-12801—Crash-recovered MSOffice encrypted documents defaulted to not to using encryption on next saveEPSS 1.3%