AI analysis
Apache OpenOffice 4.1.16 and earlier has a code execution flaw in its Java integration (CWE-426, untrusted search path). Opening a crafted, untrusted document can cause the application to run arbitrary code, including code loaded from a remote location, with the privileges of the user who opened the file. Anyone still running those versions with Java runtime integration enabled is affected. Apache expects a fix in 4.1.17, which is in release-candidate phase and not yet the general release. No public proof-of-concept is known, the issue is not in CISA KEV, and exploitation in the wild is not known.
What to do: Until Apache OpenOffice 4.1.17 is released, disable Java runtime integration in the Preferences dialog, which prevents this attack. Do not open untrusted documents. Upgrade to 4.1.17 as soon as it is generally available.
Affected
| Apache Software Foundation Apache OpenOffice | 4.1.16 and earlier |
Estimated exposure
large≈100,000–1,000,000+ desktop installations (order of magnitude) — Order-of-magnitude estimate from Apache OpenOffice’s long-standing free desktop distribution and remaining user base after the LibreOffice fork; the CVE data includes no current active-install census or internet-exposed device count.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a crafted untrusted document to trigger executing arbitrary (even remote) code when opened by the user. This issue is expected to be fixed in version 4.1.17, which is in the release candidate phase. Until then, users can mitigate this issue by disabling Java runtime integration in the Preferences dialog. This prevents the attack. If this is not possible, or as an extra precaution, you can avoid opening open untrusted files entirely. Once 4.1.17 is released, upgrade to that version to fix the issue.