CVE-2018-10583
HIGHLibreOffice 6.0.3 - Apache OpenOffice Writer 4.1.5 - Info Disclosure
Title source: llmExploitation Summary
EIP tracks 5 public exploits for CVE-2018-10583.
PoCs published by Richard Davy, MrTaherAmine, octodi, including Metasploit module auxiliary/fileformat/odt_badodt.
AI-analyzed exploit summary This script creates a malicious ODF file that exploits CVE-2018-10583 to leak NetNTLM credentials by embedding a remote object reference in the document. It automates the creation of a crafted ODT file that, when opened, triggers an SMB connection to an attacker-controlled server.
Description
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.
Exploits (5)
This script creates a malicious ODF file that exploits CVE-2018-10583 to leak NetNTLM credentials by embedding a remote object reference in the document. It automates the creation of a crafted ODT file that, when opened, triggers an SMB connection to an attacker-controlled server.
This PoC creates a malicious ODF file that exploits CVE-2018-10583 to leak NetNTLM credentials by embedding an SMB connection in the document. It uses the ezodf library to generate the file and requires a listener (e.g., Responder) to capture the credentials.
This PoC generates a malicious ODF file that exploits CVE-2018-10583 to leak NetNTLM credentials when opened in vulnerable versions of LibreOffice or OpenOffice. It creates an ODT file with a crafted content.xml that triggers an external resource request to an attacker-controlled server.
This PoC creates a malicious ODF file that exploits CVE-2018-10583 to leak NetNTLM credentials by embedding an SMB connection in the document. It uses the ezodf library to generate the file and requires a listener (e.g., Responder) to capture the credentials.
This Metasploit module generates a malicious ODT file that exploits CVE-2018-10583 in LibreOffice 6.03 and Apache OpenOffice 4.1.5. The ODT file contains a crafted content.xml that points to an SMB listener for hash capture.
References (9)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N