V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2019-9853
AST
High

LibreOffice documents can contain macros. The execution of those macros is controlled by the document security settings, typically executio…

CVSS
7.8
High
EPSS
0.03
p86
Published
2019-01-01
Updated
2019-01-01
Description

LibreOffice documents can contain macros. The execution of those macros is controlled by the document security settings, typically execution of macros are blocked by default. A URL decoding flaw existed in how the urls to the macros within the document were processed and categorized, resulting in the possibility to construct a document where macro execution bypassed the security settings. The documents were correctly detected as containing macros, and prompted the user to their existence within the documents, but macros within the document were subsequently not controlled by the security settings allowing arbitrary macro execution This issue affects: LibreOffice 6.2 series versions prior to 6.2.7; LibreOffice 6.3 series versions prior to 6.3.1.

Tags · CWE
CWE-116
CWE-838
CAPEC-73
CAPEC-81
CAPEC-85
CAPEC-104
CAPEC-468
Affected products
Libreoffice 6.2.0–6.2.6Libreoffice 6.3.0–6.3.1
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Timeline
2019-01-01
Published
2019-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: R
Required (R)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.032 · p86
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
libreofficeTracked
libreofficeTracked
libreofficeTracked
libreofficeTracked
libreofficeTracked
libreofficeTracked
libreofficeTracked
libreofficeTracked
libreoffice*Tracked
Source databases
AST
DEB
CVE
RED
UBU
Related vulnerabilities