CVE-2022-3140
Macro URL arbitrary script execution
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice links using that scheme could be constructed to call internal macros with arbitrary arguments. Which when clicked on, or activated by document events, could result in arbitrary script execution without warning. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.1; 7.3 versions prior to 7.3.6.
| CWE | CWE-20 |
| Vendor | the document foundation |
| Product | libreoffice |
| Published | Oct 11, 2022 |
| Last Updated | Aug 3, 2024 |
Stay Ahead of the Next One
Get instant alerts for the document foundation libreoffice
Be the first to know when new unknown vulnerabilities affecting the document foundation libreoffice are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
The Document Foundation / LibreOffice
7.4 < 7.4.1 7.3 < 7.3.6
References
libreoffice.org: https://www.libreoffice.org/about-us/security/advisories/CVE-2022-3140 debian.org: https://www.debian.org/security/2022/dsa-5252 lists.fedoraproject.org: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TORANVTIWWBH3DNJR4UZATAG67KZOH32/ security.gentoo.org: https://security.gentoo.org/glsa/202212-04 lists.debian.org: https://lists.debian.org/debian-lts-announce/2023/03/msg00022.html
Credits
TheSecurityDev working with Trend Micro Zero Day Initiative