CVE-2024-3044
MEDIUMLibreOffice < 7.6.7.1 - Unauthenticated Remote Code Execution via Graphic On-Click Script Binding
Title source: llmDescription
Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.
References (3)
Core 3
Core References
Mailing List, Third Party Advisory
https://lists.debian.org/debian-lts-announce/2024/05/msg00016.html
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/3TU3TYDXICKPYHMCNL7ARYYBXACEAYJ4/
Scores
CVSS v3
6.5
EPSS
0.0236
EPSS Percentile
85.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-94
CWE-356
Status
published
Products (3)
debian/debian_linux
10.0
fedoraproject/fedora
39
libreoffice/libreoffice
< 7.6.7.1
Published
May 14, 2024
Tracked Since
Feb 18, 2026