CVE-2021-25830
CRITICALONLYOFFICE DocumentServer 4.2.0.236-5.6.4.13 - Remote Code Execution via DOCT to DOCX Conversion
Title source: llmDescription
A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13. An attacker must request the conversion of the crafted file from DOCT into DOCX format. Using the chain of two other bugs related to improper string handling, an attacker can achieve remote code execution on DocumentServer.
References (6)
Core 6
Core References
Product x_refsource_misc
https://github.com/ONLYOFFICE/DocumentServer
Product x_refsource_misc
https://github.com/ONLYOFFICE/core
Third Party Advisory x_refsource_misc
https://github.com/ONLYOFFICE/core/blob/v5.6.4.13/ASCOfficePPTXFile/PPTXFormat/Logic/UniFill.cpp#L343
Third Party Advisory x_refsource_misc
https://github.com/ONLYOFFICE/core/blob/v5.6.4.13/ASCOfficePPTXFile/Editor/BinaryFileReaderWriter.cpp#L241
Third Party Advisory x_refsource_misc
https://github.com/ONLYOFFICE/core/blob/v5.6.4.13/ASCOfficePPTXFile/Editor/BinaryFileReaderWriter.cpp#L1918
Exploit, Third Party Advisory x_refsource_misc
https://github.com/merrychap/poc_exploits/tree/master/ONLYOFFICE/CVE-2021-25830
Scores
CVSS v3
9.8
EPSS
0.1176
EPSS Percentile
95.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (1)
onlyoffice/document_server
4.2.0.236 - 5.6.4.13
Published
Mar 01, 2021
Tracked Since
Feb 18, 2026