ZeroHour

CVE-2024-3044

CVSS 3.1
6.5 medium
EPSS
1%p61
Published
()
Modified
Description

Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.

Vendors
libreofficefedoraprojectdebian
Products
libreoffice, fedora, debian linux
Weakness
CWE-356, CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

In the news

No ingested article mentions this CVE yet.