CVE-2016-6803

HIGH

Apache OpenOffice < 4.1.3 - Untrusted Search Path

Title source: llm
STIX 2.1

Description

An installer defect known as an "unquoted Windows search path vulnerability" affected the Apache OpenOffice before 4.1.3 installers for Windows. The PC must have previously been infected by a Trojan Horse application (or user) running with administrative privilege. Any installer with the unquoted search path vulnerability becomes a delayed trigger for the exploit.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/94418
Issue Tracking, Vendor Advisory x_refsource_confirm
https://www.openoffice.org/security/cves/CVE-2016-6803.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1037015

Scores

CVSS v3 7.8
EPSS 0.0012
EPSS Percentile 30.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-426
Status published
Products (3)
apache/openoffice < 4.1.2
Apache Software Foundation/Apache OpenOffice 4.0.0 to 4.1.2
Apache Software Foundation/Apache OpenOffice Older versions, including some using the previous OpenOffice.org brand, are also affected.
Published Nov 13, 2017
Tracked Since Feb 18, 2026