CVE-2025-0514

HIGH

LibreOffice 24.8.0-24.8.5.0 - Unauthenticated Arbitrary Windows Executable Execution via Hyperlink Activation

Title source: llm
STIX 2.1

Description

Improper Input Validation vulnerability in The Document Foundation LibreOffice allows Windows Executable hyperlink targets to be executed unconditionally on activation.This issue affects LibreOffice: from 24.8 before < 24.8.5.

References (1)

Core 1

Scores

CVSS v3 7.8
EPSS 0.0032
EPSS Percentile 23.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20
Status published
Products (1)
libreoffice/libreoffice 24.8.0.0 - 24.8.5.1
Published Feb 25, 2025
Tracked Since Feb 18, 2026