Description
In the LibreOffice 7-1 series in versions prior to 7.1.2, and in the 7-0 series in versions prior to 7.0.5, the denylist can be circumvented by manipulating the link so it doesn't match the denylist but results in ShellExecute attempting to launch an executable type.
Related CPE's
a
libreoffice
libreoffice
2
References
https://positive.security/blog/url-open-rce#open-libreoffice
ExploitThird Party Advisory
https://positive.security/blog/url-open-rce#open-libreoffice
ExploitThird Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 · High
Information
Source identifier
Vulnerability status
Modified
Published
2021-05-03T10:15:07.417Z
4 years agoLast modified
2024-11-21T04:55:10.970Z
1 year ago