๐Ÿ” CVE Alert

CVE-2022-3140

UNKNOWN 0.0

Macro URL arbitrary script execution

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice links using that scheme could be constructed to call internal macros with arbitrary arguments. Which when clicked on, or activated by document events, could result in arbitrary script execution without warning. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.1; 7.3 versions prior to 7.3.6.

CWE CWE-20
Vendor the document foundation
Product libreoffice
Published Oct 11, 2022
Last Updated Aug 3, 2024
Stay Ahead of the Next One

Get instant alerts for the document foundation libreoffice

Be the first to know when new unknown vulnerabilities affecting the document foundation libreoffice are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

The Document Foundation / LibreOffice
7.4 < 7.4.1 7.3 < 7.3.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
libreoffice.org: https://www.libreoffice.org/about-us/security/advisories/CVE-2022-3140 debian.org: https://www.debian.org/security/2022/dsa-5252 lists.fedoraproject.org: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TORANVTIWWBH3DNJR4UZATAG67KZOH32/ security.gentoo.org: https://security.gentoo.org/glsa/202212-04 lists.debian.org: https://lists.debian.org/debian-lts-announce/2023/03/msg00022.html

Credits

TheSecurityDev working with Trend Micro Zero Day Initiative