CVE-2024-7788

HIGH

Libreoffice < 24.2.5 - Signature Verification Bypass

Title source: rule
STIX 2.1

Description

Improper Digital Signature Invalidation  vulnerability in Zip Repair Mode of The Document Foundation LibreOffice allows Signature forgery vulnerability in LibreOfficeThis issue affects LibreOffice: from 24.2 before < 24.2.5.

Scores

CVSS v3 7.8
EPSS 0.0006
EPSS Percentile 19.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-347
Status published
Products (1)
libreoffice/libreoffice 24.2.0 - 24.2.5
Published Sep 17, 2024
Tracked Since Feb 18, 2026